Impact
The vulnerability is an out‑of‑bounds read and write in Google Chrome’s GFX engine. When triggered by malicious network traffic, an attacker can read from or write to arbitrary memory inside the browser process, falling under CWE‑125 and CWE‑787. The Chrome engineering team has rated the problem as medium severity with a CVSS score of 5.4, indicating a meaningful risk if exploited.
Affected Systems
Google Chrome desktop installations on all operating systems before version 148.0.7778.96 are affected. The GFX subsystem is used on Windows, macOS and Linux, and the issue does not require local or privileged access to impact a user.
Risk and Exploitability
The CVSS score of 5.4 places the vulnerability in a moderate risk category. No EPSS value is available, so the exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed. The likely attack vector is remote, via crafted network traffic that the GFX engine processes.
OpenCVE Enrichment
Debian DSA