Impact
Uninitialized Use in ANGLE, a component used for graphics rendering in Google Chrome, allows a remote attacker to read memory that was not properly initialized. When a specially crafted web page is loaded, the attacker can leak cross‑origin data from the victim’s browser, potentially exposing sensitive information. The vulnerability is classified as a medium severity issue, indicating that exploitation would have significant but not catastrophic impact on confidentiality.
Affected Systems
The issue affects Google Chrome versions prior to 149.0.7827.53 on all platforms supported by the browser. Users running any of these earlier builds are vulnerable until the fix is applied. No other browsers or versions are affected.
Risk and Exploitability
The vulnerability can be triggered by any web page that the user visits, so the attack vector is remote via an HTTP or HTTPS request. The EPSS score of <1% and a CVSS score of 6.5 indicate a low probability and medium severity risk, and the issue is not listed in CISA’s KEV catalog. Successful exploitation would allow a malicious website to read memory that was not properly initialized, resulting in cross‑origin data leakage without requiring elevated privileges.
OpenCVE Enrichment
Debian DSA