Google Chrome on Windows contains an out-of-bounds read in the ANGLE component, classified as CWE-125. The attacker controls a crafted HTML page, and the record states that a remote attacker may potentially cause Chrome to read memory outside the expected bounds and outside the sandbox. The described path is browser-reachable through HTML processing, but the available evidence does not identify the relevant API, data structure, trigger sequence, or required browser state. The plausible security outcome is disclosure of data from the browser process, although the type of data and repeatability are unknown. The available evidence does not establish code execution, privilege escalation, or data modification.