Impact
Uninitialized memory in the ANGLE component of Google Chrome on Windows, before version 155.0.8059.39, can be triggered by a crafted HTML page. This flaw allows a remote attacker to read memory outside the browser sandbox, potentially exposing sensitive data. The Chromium security team labeled the severity as High.
Affected Systems
Any Windows system running Google Chrome prior to version 155.0.8059.39 is affected. The vulnerability is limited to the desktop stable channel and does not impact other Chrome variants or operating systems.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the high CVSS rating and the ability to trigger the exploit via a standard web page make it a serious threat. The most likely attack vector is a malicious website that the user visits; the exploitation requires the victim to open the page in Chrome, after which the attacker can read arbitrary memory.
OpenCVE Enrichment