Impact
An uninitialized cast in Google Chrome versions prior to 150.0.7871.47 permits an attacker on the same local network segment to read uninitialized memory and extract potentially sensitive data from process memory. The flaw is a use‑of‑uninitialized‑data weakness (CWE‑457) that results in a disclosure of confidential information without requiring authentication.
Affected Systems
The vulnerability affects any machine running Google Chrome browsers with build numbers older than 150.0.7871.47. No operating‑system or platform restrictions are noted; any device on the local network where this Chrome version is installed is potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to be on the same local network segment and to send specially crafted traffic that triggers the uninitialized cast, making it a local‑segment vulnerability with limited public exploitation evidence.
OpenCVE Enrichment
Debian DLA
Debian DSA