Impact
Uninitialized memory in WebGPU allows a determined attacker to craft an HTML page that creates a GPU resource in an uninitialized state, enabling the attacker to read data that belongs to other web origins. The vulnerability is a form of improper resource management (CWE-908) and can lead to covert disclosure of sensitive information across origin boundaries. The stated Chromium severity is high, but the CVSS score of 4.3 indicates a moderate overall impact.
Affected Systems
Google Chrome for desktop users running any version prior to 154.0.8037.92 is susceptible. Older releases before the 154.x series lack the patch that properly initializes GPU resources used by WebGPU.
Risk and Exploitability
No EPSS score is available, so the assessed exploitation likelihood remains uncertain. The CVSS score of 4.3 reflects moderate severity, and the vulnerability is not listed in the CISA KEV catalogue. Attackers would need to deliver a crafted web page to a victim’s browser, which means the vulnerability is exploitable remotely without additional privileges. Even though no public exploit has been documented, the theoretical risk remains notable for sites that rely on WebGPU for graphics or compute workloads.
OpenCVE Enrichment