Impact
An out‑of‑bounds read bug in ANGLE allows a remote attacker to read memory outside the sandbox by delivering a crafted HTML page. This vulnerability can expose sensitive data but does not provide code execution or denial of service.
Affected Systems
Google Chrome is affected in all releases prior to 153.0.8010.36. Users running older versions are vulnerable until an update is installed.
Risk and Exploitability
The flaw can be triggered over the internet by loading a malicious page. The CVSS score of 4.3 marks it as Medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV. The Chromium severity rating is medium, indicating a moderate risk if the affected browser is enabled in a user’s environment.
OpenCVE Enrichment
Debian DLA
Debian DSA