Impact
An out-of-bounds read in ANGLE, the graphics abstraction layer used by Chrome, can be triggered by a crafted HTML page. An adversary who convinces an end user to load such a page can cause Chrome to read memory it should not, which in turn can lead to arbitrary code execution on the affected system. The weakness is identified as CWE-125, an out-of-bounds read that can be leveraged to compromise confidentiality, integrity, and availability of the victim’s environment.
Affected Systems
Windows users running Google Chrome versions earlier than 148.0.7778.216 are affected. The vulnerability applies to the desktop Chrome binary on all Windows operating systems, regardless of version, as the ANGLE component is used across the platform. No other operating systems or product variants are listed as impacted.
Risk and Exploitability
Chrome assigns the issue a high severity rating, with a CVSS score of 8.8. Because the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, detailed exploitation probability is unknown, but the remote code execution possibility and the ease of deployment via a malicious web page make the risk significant. The vulnerability is likely to be exploitable from any network that can deliver a crafted HTML page to a user, such as public Wi‑Fi or insecure corporate networks. No specific preconditions beyond browsing a malicious page are required, so the attack can occur in a wide range of environments.
OpenCVE Enrichment