Impact
A flaw in the Dawn rendering engine of Google Chrome on macOS allows a remote attacker to read memory beyond the sandbox boundaries. The vulnerability results from an uninitialized resource that can be exploited by delivering a specially crafted HTML page to the user. This permits the attacker to access sensitive data stored in the renderer process, potentially compromising confidentiality. The weakness corresponds to CWE-908: Uninitialized Resource.
Affected Systems
Affected systems are macOS users running Google Chrome before version 155.0.8059.39. The issue exists in Chrome’s Desktop channel on macOS; the advisory references the stable channel update to 155.0.8059.39 that addresses the uninitialized Dawn resource.
Risk and Exploitability
No CVSS score is provided but the security advisory classifies it as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is a malicious web page loaded in the browser; the attacker must convince the user to visit the page. Once the page loads, the renderer can read arbitrary memory, giving the attacker the ability to exfiltrate confidential information.
OpenCVE Enrichment