Impact
An uninitialized variable in the video codec subsystem of Google Chrome on Linux and ChromeOS can cause the browser to reveal cross‑origin data when a specially crafted video file is processed, allowing a remote attacker to read memory contents that should be protected. The flaw is a classic example of an uninitialized use weakness, identified as CWE‑457 and CWE‑824, and the official Chromium severity rating is high.
Affected Systems
The vulnerability affects the Chrome browser for Linux and ChromeOS versions prior to 149.0.7827.103 from Google. No other vendors or products are listed as affected.
Risk and Exploitability
The flaw can be triggered by any user who opens a malicious video file in the affected Chrome installation, making it a remote attack vector that does not require elevated privileges. Because the vulnerability relies on uninitialized data, exploitation is likely to succeed when a user interacts with a crafted file, such as by clicking a link or downloading a video. The CVSS score of 4.3 indicates a moderate level of severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating that it has not been observed in widespread, active exploitation.
OpenCVE Enrichment
Debian DSA