Impact
The vulnerability is a race condition in the Speech component of Google Chrome that allows a compromised renderer process to read arbitrary memory contents. Because the renderer handles user data and sensitive information, an attacker can expose proprietary or confidential data from process memory. The flaw is categorized as CWE‑362 and is considered medium severity by Chromium.
Affected Systems
Affected systems are Google Chrome desktop browsers on any operating system before version 148.0.7778.96. The security fix is included in the stable channel update released after Chrome 148.0.7778.96.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the vulnerability is not included in the CISA KEV catalog. The EPSS score is not available, so the likelihood of exploitation cannot be determined. Successful exploitation requires the attacker to already have control over the renderer process, which typically implies a prior compromise. Consequently, while the risk of information disclosure is significant if the renderer is compromised, the overall attack surface is less than for vulnerabilities that allow arbitrary code execution from a blind remote position.
OpenCVE Enrichment
Debian DSA