Impact
An out‑of‑bounds read occurs in the Chromoting component of Google Chrome for Windows before version 153.0.8010.36. The flaw allows a local attacker to read memory locations that lie outside the Sandbox boundary through a local program, potentially exposing sensitive information stored in process memory. The CVE is rated High in Chromium severity, reflecting the seriousness of the data disclosure risk, although it does not provide a pathway to remote code execution.
Affected Systems
Google Chrome on Windows installations running any version earlier than 153.0.8010.36 are affected. The vulnerability is limited to Windows platforms and does not impact Chrome running on other operating systems.
Risk and Exploitability
The CVSS score of 2.7 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation under normal circumstances. The vulnerability is not listed in the CISA KEV catalog. The flaw allows a local attacker with access to a victim’s machine to execute a local program that interacts with Chrome’s Chromoting interface and read memory addresses beyond the sandbox boundary. No remote attack vector is documented, so the attack requires local presence and a program that can communicate with Chrome. While the risk to overall system compromise is limited, the capability to read arbitrary memory could expose sensitive data, making it a data disclosure risk. Updating to Chrome 153.0.8010.36 or newer eliminates the flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA