Impact
A flaw in Chrome's media component allows a remote attacker who already has control over the renderer process to read memory addresses outside the sandbox. The vulnerability is an out‑of‑bounds read, identified as CWE‑125, that can expose sensitive data held in memory. The CVSS score of 3.4 indicates medium severity, and the issue does not provide a path to arbitrary code execution, but it does enable information disclosure across the sandbox.
Affected Systems
Google Chrome stable channel versions earlier than 152.0.7977.65 are susceptible. The affected component is the media subsystem that processes HTML content.
Risk and Exploitability
The EPSS score indicates less than 1%, and the issue is not listed in the CISA KEV catalog, indicating no evidence of active exploitation yet. The CVSS score of 3.4 shows medium severity, and the attack vector requires a remote attacker to deliver a crafted HTML page that is rendered in a compromised renderer process. Successful exploitation would allow the attacker to read data that should be isolated from userland, potentially leaking private information. The risk is moderate, largely depending on the likelihood that adversaries can first compromise the renderer process, which may involve additional vulnerabilities or social engineering.
OpenCVE Enrichment
Debian DLA
Debian DSA