Impact
An uninitialized use fault in ANGLE, Chrome’s graphics abstraction layer, allows a remote attacker to read data from another as CWE‑457, leads to cross‑origin data leakage and is labeled High in Chromium. This represents a significant privacy impact for users whose browsers have not received the latest patch.
Affected Systems
Google Chrome users on macOS running any version older than 150.0.7871.47 are affected. The vulnerability is confined to that product version and operating system; no other browsers or operating systems are explicitly mentioned in the advisory.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the user to open a maliciously constructed HTML page, and no active or publicly available exploits are documented, so the practical risk hinges on exposure to such content.
OpenCVE Enrichment
Debian DLA
Debian DSA