Impact
A memory dereference bug in Chrome’s Dawn rendering engine allows a specially crafted HTML page to read data that was not initialized in the process’s heap. This is an instance of uninitialized use (CWE-457) and a direct memory read (CWE-824), enabling an attacker to obtain potentially sensitive information from memory but not execute arbitrary code.
Affected Systems
Google Chrome desktop browsers using the Dawn engine in any version prior to 149.0.7827.53 are affected. Users on these builds are at risk until the browser is updated to the fixed version.
Risk and Exploitability
The vulnerability is triggered remotely when a victim loads a malicious HTML page. The CVSS score is 6.5, and the EPSS score is < 1%, indicating a modest but non‑zero likelihood of exploitation. The issue is not listed in the CISA KEV catalog, suggesting it is not among the most widely observed exploits. The medium severity rating indicates a meaningful privacy risk that should be addressed promptly.
OpenCVE Enrichment
Debian DSA