Impact
An out-of-bounds read vulnerability exists in the GPU driver used by Google Chrome on Linux prior to version 148.0.7778.168. The flaw allows a remote attacker who has already compromised the renderer process to read memory that belongs to other origins. The data leakage constitutes a confidentiality compromise, potentially exposing inter-origin information to the attacker. This weakness is identified as CWE-125, a classic buffer overread problem.
Affected Systems
Google Chrome for Linux, versions earlier than 148.0.7778.168. The vulnerability affects users running the stable channel prior to the advertised update and is mitigated by installing the new stable release from the publisher’s official channel.
Risk and Exploitability
The CVSS score is 3.1, and the EPSS score is less than 1%. It is not listed in CISA’s KEV catalog, indicating a relatively low exploitation probability in the absence of widespread attacks. The attacker must first compromise the renderer process, a non-trivial prerequisite that typically requires exploitation of another vulnerability. The Chromium security severity is rated Medium, indicating a significant threat when the renderer compromise condition is satisfied, but the overall risk remains lower than for remote code execution scenarios.
OpenCVE Enrichment
Debian DSA