Impact
The vulnerability is an out‑of‑bounds read in Chrome's GPU code on Mac and Windows before 148.0.7778.168. A remote attacker who has already compromised the renderer process can trigger a crafted HTML page to read sensitive data from process memory. This flaw can lead to confidential data leaks. The weakness is identified as CWE‑125.
Affected Systems
Google Chrome on macOS and Windows operating systems, versions earlier than 148.0.7778.168, are affected. This includes all Chrome stable releases prior to that build across the two platforms.
Risk and Exploitability
Chromium labels the flaw as Medium severity with a CVSS score of 5.3. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that an attacker first gain control of the renderer process, then serve a malicious HTML page that triggers the out‑of‑bounds read. Given the lack of published exploitation tools, the likelihood remains uncertain, but the medium severity and memory disclosure potential underscore the importance of timely patching.
OpenCVE Enrichment
Debian DSA