Impact
An uninitialized GPU resource in Google Chrome on Android allows a compromised renderer process to read memory outside the sandbox through a crafted HTML page. The vulnerability exploits a flaw in the way GPU memory is allocated and initialized, permitting the attacker to access data that should remain isolated to the renderer. The primary consequence is the potential for sensitive information disclosure, which could be leveraged if additional exploitation paths are available. The Chrome security team has rated the issue as medium severity, indicating the risk is significant but not immediate catastrophic.
Affected Systems
All Android users running Google Chrome versions earlier than 155.0.8059.39 are affected. The vulnerability resides in the GPU code that interfaces with the renderer process; any device that installs the affected Chrome build on Android is within scope. Versions 155.0.8059.39 and later contain the remediation.
Risk and Exploitability
The CVE has no EPSS data and is not listed in CISA’s KEV catalog, suggesting limited public exploitation. However, the vulnerability requires an attacker to have already compromised the renderer process, which typically demands a successful drive‑by or phishing attack. The medium severity rating reflects the potential impact on information confidentiality, while the lack of public exploit signatures mitigates immediate risk, yet the possibility remains for targeted exploitation in the future.
OpenCVE Enrichment