Impact
The vulnerability is an inappropriate implementation in the V8 engine of Google Chrome, allowing a remote attacker to read potentially sensitive data from process memory through a crafted HTML page. This flaw falls under CWE-200 and CWE-825, exposing information and potentially compromising data confidentiality. The likely attack vector is a remote web page delivered via the browser.
Affected Systems
The vulnerable Chrome builds are any releases prior to 148.0.7778.96. They run on Windows, macOS, and Linux operating systems and can be accessed through standard user browsing.
Risk and Exploitability
Chromium labels the issue as low severity, with a CVSS score of 4.3, an EPSS score of less than 1%, and it is not listed in the CISA KEV catalog. The exploit requires user interaction with a malicious web page and does not provide code execution or privilege escalation. Based on the metrics, the practical risk is low to moderate, with exploitation unlikely to be widespread.
OpenCVE Enrichment
Debian DSA