Impact
A flaw in Chrome’s audio handling allows a remote attacker who has already compromised the renderer process to acquire sensitive information from process memory. The vulnerability stems from an uninitialized variable used during audio processing, allowing memory to be read that should not be exposed. The impact is a privacy breach, potentially revealing user data or application secrets, but it does not grant arbitrary code execution or system compromise on its own.
Affected Systems
The affected product is Google Chrome. Versions prior to 149.0.7827.53 are impacted. No further version details are listed beyond the mentioned release.
Risk and Exploitability
The CVSS score is not disclosed, but the description indicates a medium severity. Because the EPSS score is not available, the likelihood of exploitation remains uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation currently. The attack requires a pre‑existing compromise of the renderer process, so the vector is local to a compromised process rather than a network‑initiated attack.
OpenCVE Enrichment