Impact
An uninitialized variable in the video codec subsystem of Google Chrome on Linux and ChromeOS can cause the browser to reveal cross‑origin data when a specially crafted video file is processed, allowing a remote attacker to read memory contents that should be protected. The flaw is a classic example of an uninitialized use weakness, identified as CWE‑457, and the official Chromium severity rating is high.
Affected Systems
The vulnerability affects the Chrome browser for Linux and ChromeOS versions prior to 149.0.7827.103 from Google. No other vendors or products are listed as affected.
Risk and Exploitability
The flaw can be triggered by any user who opens a malicious video file in the affected Chrome installation, making it a remote attack vector that does not require elevated privileges. Because the vulnerability relies on uninitialized data, exploitation is likely to succeed in the presence of user interaction, such as clicking a link or downloading a file. The CVSS score of 4.3 indicates a moderate level of severity, and the EPSS score is not available, suggesting limited evidence of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating that while the issue is moderate severity it has not been observed in widespread, active exploitation.
OpenCVE Enrichment