Impact
Uninitialized variable use in the ANGLE rendering engine of Google Chrome potentially exposes cross‑origin data. An attacker who can influence the renderer process, for example by loading a specially crafted page, may read information from sites that the user accesses, violating confidentiality. This inference is based on the attack vector described.
Affected Systems
Google Chrome browsers running versions earlier than 149.0.7827.53 are affected. The vulnerability is present in the ANGLE component used by the renderer process.
Risk and Exploitability
The flaw has a CVSS score of 6.5, which corresponds to Medium severity on the standard scale. The EPSS score is < 1%, indicating a very low likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. Exploitation requires an attacker to already compromise the renderer process, which typically means the user has been tricked into visiting a malicious page or has had local compromise. Once the renderer is under attacker control, crafted HTML can trigger the uninitialized variable use and leak cross‑origin data. The scenario is inferred; the description does not explicitly state whether the exploit is interactive or the exact method of triggering the bug.
OpenCVE Enrichment
Debian DSA