Impact
An out‑of‑bounds read occurs in Chrome’s DataTransfer component, allowing a local attacker to read memory outside the sandboxed environment. The flaw is classified as CWE‑125 and can leak sensitive information that resides in protected memory areas. The vulnerability is limited to local code execution contexts and does not provide a path to arbitrary code execution or system compromise.
Affected Systems
Google Chrome desktop builds prior to version 153.0.8010.52 are affected. The issue was identified in the stable channel and addressed in the 153.0.8010.52 release. Users operating earlier Chrome versions are at risk if they run untrusted local programs.
Risk and Exploitability
The CVSS score of 6.3 reflects a medium severity condition, while an EPSS score of less than 1% indicates a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, suggesting it has not been actively exploited publicly. Exploitation requires a local attacker to successfully persuade a user to run a crafted program, so the primary attack vector is local social engineering. Once executed, the vulnerability allows memory disclosure that could expose credentials or other private data.
OpenCVE Enrichment
Debian DLA
Debian DSA