Impact
An uninitialized resource in Chrome’s Media component on Windows allows a remote attacker who has already compromised the renderer process to read memory outside the sandbox through a crafted HTML page. This flaw is identified as CWE‑908 (Uninitialized Resource Used) and could expose sensitive data from the renderer, leading to information disclosure. The vulnerability is not a direct code execution flaw but enables a low‑barrier path to leak memory content.
Affected Systems
The issue affects Google Chrome running on Windows that are older than version 154.0.8037.92, which is the release that contains the remediation. Users of the stable channel are at risk if they have not installed the update provided in the September 2026 release notes.
Risk and Exploitability
The CVSS score of 3.4 classifies the risk as low, however Chromium’s internal severity rating is high due to the potential for memory exposure. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The attack requires an attacker to already have access to the renderer process or to deceive a user into loading a malicious page that interacts with the vulnerable media handler. While the exploitation path is not trivial, the combination of a compromised renderer and crafted HTML provides a realistic condition for memory disclosure.
OpenCVE Enrichment