Impact
An uninitialized variable in ANGLE, the graphics abstraction layer used by Chrome, can allow a remote attacker to read potentially sensitive data from process memory. The flaw is identified as CWE-457, where the program fails to initialize a buffer before use. When triggered by a specially crafted HTML page, the attacker may obtain information that could aid in further exploitation or privacy compromise. Chromium classifies the severity as Medium, indicating a non‑critical but noticeable risk to confidentiality.
Affected Systems
Google Chrome is the affected product. Versions prior to 149.0.7827.53 are vulnerable. Any browsers built on the ANGLE stack that have not been updated beyond that revision fall into the risk zone.
Risk and Exploitability
The exploitability is moderate; the flaw is accessed remotely through a web page, so a malicious site can trigger it. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation in the wild. However, because it is a memory disclosure, the potential impact on user data remains significant, and the absence of a public exploit does not preclude targeted or automated discovery in the future.
OpenCVE Enrichment