Impact
An out-of-bounds read in the ANGLE graphics abstraction layer allows a remote attacker to read memory outside the sandbox by loading a crafted HTML page. The flaw is a classic buffer overread (CWE-125) and does not grant code execution, but it permits the attacker to retrieve sensitive data from the browser process.
Affected Systems
Google Chrome is affected, specifically versions prior to 153.0.8010.36. Users running any of those versions should be aware that a malicious HTML page served to the browser can exploit the memory misread.
Risk and Exploitability
The vulnerability is exploitable via the network as a remote attacker controlling a web page can supply the malicious content. While no public exploits are listed and the issue is not in CISA's KEV catalog, the CVSS score of 4.3 and the high severity designation suggest a potential for confidentiality exposure. The EPSS score of < 1% indicates that public exploitation is unlikely, but the presence of a remote attack vector means timely patching is essential to mitigate risk.
OpenCVE Enrichment
Debian DLA
Debian DSA