Impact
Uninitialized use of a GPU variable in Google Chrome for Android (CWE-457: Uninitialized Local Variable) permits an attacker to craft a specific HTML page that, when opened in the browser, causes the GPU code to read uninitialized memory from the process. Through this mechanism the attacker may obtain potentially sensitive data stored in the process’s address space. Chromium classifies the flaw as medium severity, indicating it can expose information but does not result in full code execution.
Affected Systems
Google Chrome on Android devices running any version prior to 150.0.7871.47. No other vendors or products are affected.
Risk and Exploitability
The CVSS score is 6.5, indicating medium severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation at this time. Based on the description, it is inferred that attacks would likely occur via phishing or malicious websites that serve the crafted page to a user’s browser. While detection is difficult, the exploit would be limited to data disclosure and requires the user to visit a malicious webpage within Chrome.
OpenCVE Enrichment
Debian DLA
Debian DSA