Impact
Out‑of‑bounds read occurs in the Tint component of Google Chrome, allowing a remote attacker to read memory within the browser’s sandbox. This could expose sensitive internal data of the browsing context but does not permit code execution at this time. The flaw is categorized as CWE‑125 and is rated as low severity by Chromium’s own assessment. The impact is limited to confidentiality compromise of sandboxed content accessed by a crafted HTML page.
Affected Systems
Google Chrome web browsers on all platforms running a version prior to 153.0.8010.36 are affected. Any installation that has not yet updated beyond that release must be considered vulnerable.
Risk and Exploitability
The CVSS score is 4.3, and the EPSS score is < 1%, indicating a low likelihood of widespread exploitation. No known public exploit exists and the vulnerability is not included in CISA’s KEV catalog, suggesting a low likelihood of widespread exploitation. The attack vector is inferred to require delivery of a specially crafted HTML page to the target through a standard web connection, making it theoretically feasible from any remote location that can reach the victim’s browser.
OpenCVE Enrichment
Debian DLA
Debian DSA