Impact
The vulnerability occurs when ANGLE in Google Chrome does not properly initialize a variable, allowing a remote attacker to read data across origins through a specially crafted HTML page. This flaw enables an attacker to exfiltrate sensitive information from the victim’s browser sessions without modifying the user’s data or system state, thereby compromising confidentiality for any user who visits a malicious page. The weakness is classified under CWE-457, indicating uninitialized variable usage.
Affected Systems
The affected product is Google Chrome. Versions prior to 149.0.7827.53 are vulnerable, so any Chrome build below that release is at risk.
Risk and Exploitability
The vulnerability is exploitable via the web, as a crafted HTML page can trigger the leak. No EPSS score is available, and it is not listed in the CISA KEV catalog, though the impact remains notable. The CVSS score is not provided in the data, but the issue is considered medium severity. Attackers could gain the victim’s data by hosting a malicious page that leverages the uninitialized variable in ANGLE to read cross-origin content.
OpenCVE Enrichment