Impact
The vulnerability is an uninitialized use in the Dawn rendering engine in Google Chrome, which allows a remote attacker to leak cross‑origin data through a crafted HTML page. Only the confidentiality of data is affected; no evidence of remote code execution or denial of service is stated. The weakness is a CWE‑457 type defect where an uninitialized variable leads to unintended data read, and it also aligns with CWE‑824, demonstrating improper use of uninitialized memory that results in information disclosure.
Affected Systems
Google Chrome for Windows versions prior to 149.0.7827.53 are affected. The issue is specific to the Dawn component in those builds.
Risk and Exploitability
The EPSS score is available and is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating limited publicly known exploitation. The likely attack vector is a web‑based attack where the attacker serves a malicious HTML page that triggers the uninitialized use. A CVSS score of 6.5 is supplied, indicating Medium severity, consistent with Chromium's Medium rating.
OpenCVE Enrichment
Debian DSA