Impact
An integer overflow in ANGLE, the graphics abstraction layer used by Google Chrome, can be triggered on a crafted HTML page. The flaw allows an attacker to read data from a different origin, effectively leaking information that should be isolated by the browser's same‑origin policy. The vulnerability is classified as medium severity by Chromium's internal metrics, indicating a noticeable impact but not an immediate catastrophic failure.
Affected Systems
Google Chrome versions prior to 148.0.7778.96 are vulnerable. The issue affects all desktop installations of Chrome that have not yet been updated to this version or newer.
Risk and Exploitability
Because the flaw is triggered via a specially crafted web page, any web browser user could be targeted. The exact likelihood of exploitation is not quantified by an EPSS score and the vulnerability is not listed in CISA's KEV catalog, suggesting moderate exposure risk. The attack vector is inferred to be remote, requiring the victim to load malicious content from an attacker-controlled site. Exploitation would lead to unauthorized disclosure of cross‑origin data but does not necessarily provide code execution or privilege escalation. The CVSS score for this vulnerability is 4.3, reflecting its medium severity.
OpenCVE Enrichment