Impact
Integer overflow in the Compositing component of Google Chrome allows a crafted web page to read memory belonging to another origin. The flaw can enable an attacker to obtain data that is protected by the same‑origin policy, effectively bypassing cross‑origin restrictions. This vulnerability is classified as a logic flaw leading to confidentiality loss.
Affected Systems
Google Chrome versions earlier than 153.0.8010.47 on desktop platforms are affected. The issue originates from the Chromium project and is limited to browsers built from Chromium releases before the specified version.
Risk and Exploitability
The CVSS score of 4.3 places the issue in the low to moderate range. EPSS indicates less than 1% likelihood of exploitation, and it is not listed in CISA’s KEV catalog. The attack requires an attacker to host a malicious HTML page that the victim loads. While technical barriers are present, the presence of the overflow provides a straightforward path once the page is visited.
OpenCVE Enrichment