Impact
Uninitialized GPU resources in Chrome before version 154.0.8037.92 allow a remote attacker who has already compromised the renderer process to read memory beyond the sandbox. The flaw originates from a buffer that is not properly initialized before use, enabling the attacker to access data that should remain protected by the browser's security model. This can expose sensitive information such as clipboard contents, browsing history, or credentials that the renderer may hold, thereby compromising confidentiality. The weakness is characterized as CWE-908: Uninitialized Resource.
Affected Systems
Google Chrome 154.0.8037.91 and earlier. The issue is not limited to a specific platform; any desktop build of Chrome using the affected GPU stack is susceptible.
Risk and Exploitability
The CVSS score of 3.4 indicates a low to moderate severity, and the EPSS is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker who has already obtained code‑execution privileges in the renderer process, likely via another vulnerability or social‑engineering attack. Once the renderer is compromised, an attacker can craft an HTML payload to trigger the uninitialized resource and read data from memory outside the intended sandbox scope.
OpenCVE Enrichment