Impact
A use of an uninitialized variable in the Dawn graphics engine of Google Chrome can allow a remote attacker to read cross‑origin data via a crafted HTML page. The flaw does not grant code execution but leaks confidential information that from another origin. The underlying weakness involves CWE‑457 and the related CWE‑824.
Affected Systems
All users running Google Chrome versions older than 149.0.7827.53 are affected. The vulnerability is listed under the product Google:Chrome and affects any platform that hosts that product. No specific operating systems or architectures are mentioned in the CVE data.
Risk and Exploitability
The issue carries a CVSS score of 7.4, indicating high severity, but an EPSS score of <1% indicates a very low probability of exploitation. The CVE is not listed in the CISA KEV catalog. Exploitation requires a victim to load a maliciously crafted page, so it relies on user interaction or social engineering. While no public exploits are known, a successful data leak could expose sensitive information from cross‑origin contexts.
OpenCVE Enrichment
Debian DSA