Impact
The vulnerability is an uninitialized use in the Skia graphics engine within Google Chrome. An attacker who has already compromised the renderer process can read memory that the process should not access, potentially exposing sensitive information. This weakness is classified as CWE-457 and CWE-824, representing uninitialized use and use-after-free read vulnerabilities, respectively. Chromium labels the severity of this issue as medium.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected. The issue applies to the Chrome stable channel releases that have not yet incorporated the available patch.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity. The EPSS score is less than 1%, reflecting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a prior compromise of the renderer process, as stated in the CVE description, after which memory disclosure becomes possible. The overall likelihood of exploitation remains low due to the low EPSS score and the need for control of the renderer process.
OpenCVE Enrichment
Debian DSA