Impact
An out‑of‑bounds read vulnerability in the FileSystem component of Google Chrome prior to version 152.0.7977.65 allows a remote attacker to read memory outside the browser sandbox via a crafted HTML page. The flaw enables the attacker to read sensitive data placed in adjacent memory areas, potentially exposing confidential information. The vulnerability is classified as low severity by Chromium. This vulnerability maps to CWE‑125.
Affected Systems
The affected product is Google Chrome. All Chrome releases earlier than 152.0.7977.65 are impacted; the issue is fixed in version 152.0.7977.65 and later.
Risk and Exploitability
Exploit requires the attacker to supply a malicious HTML page, typically through social engineering, and the victim must open it in Chrome. Based on the description, it is inferred that the attack vector is Remote via Browser. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS assessment is 6.5, indicating a moderate risk level.
OpenCVE Enrichment
Debian DLA
Debian DSA