Impact
The vulnerability is an integer overflow in Google Chrome’s ANGLE graphics component. In versions prior to 148.0.7778.216, a specially crafted HTML page can cause the renderer process to perform an out‑of‑bounds memory read. The CVE description does not specify which data can be obtained, but such a read could potentially expose sensitive information present in the renderer’s memory.
Affected Systems
All desktop installations of Google Chrome running a version earlier than 148.0.7778.216 are affected, independent of operating system. The integer overflow flaw is fixed in Chrome 148.0.7778.216 and later releases.
Risk and Exploitability
The CVSS score of 4.3 places the flaw in the low‑to‑moderate range, while an EPSS score of less than 1% indicates a very low likelihood of widespread exploitation. The issue is not listed in CISA KEV. An attacker would need only to deliver a crafted page to a victim’s browser; no publicly available exploit is known. The out‑of‑bounds read provides a basic data‑exfiltration primitive that could be leveraged against a user who visits untrusted sites.
OpenCVE Enrichment
Debian DSA