Impact
The flaw is an uninitialized-use bug in the media component of Google Chrome. If an attacker has already compromised the renderer process—such as by injecting code into that process—they can read arbitrary memory from that process through a specially crafted HTML page. The bug is classified as CWE-457, CWE-824, and CWE-908, and its primary effect is leaking potentially sensitive data from renderer memory, which can be used in follow‑on attacks. The vulnerability does not allow remote code execution or privilege escalation by itself, but the information disclosed could aid in further exploitation.
Affected Systems
All versions of Google Chrome prior to 149.0.7827.53 on Windows, macOS, and Linux are affected. The issue manifests only on installations where the renderer process is compromised, so users browsing malicious content in an affected build are at risk.
Risk and Exploitability
Chromium rates the issue as medium severity with a CVSS score of 6.5. The EPSS score is reported as <1%, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation at this time. Nonetheless, because the flaw requires that the attacker already possess code execution in the renderer, the exploitability is limited compared to remote code‑execution bugs, but the potential data leakage remains a credible risk in environments that allow arbitrary media or script execution from untrusted sites.
OpenCVE Enrichment
Debian DSA