Impact
An uninitialized use of a CSS variable in Google Chrome for Android allows a remote attacker to read potentially sensitive data from the browser process memory through a specially crafted HTML page, corresponding to CWE-457. The impact is the inadvertent leakage of private information that could be leveraged by an attacker gaining access to confidential data stored in memory. The Chromium security severity is classified as medium.
Affected Systems
Google Chrome on Android devices prior to version 150.0.7871.47 are affected only in Android builds of Chrome before that specific release.
Risk and Exploitability
The exploit can be triggered by delivering a specially crafted HTML page to the device, indicating a remote attack vector. The CVSS score is 6.5; the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting no known wild exploitation. Chromium assigns a medium security severity to this issue, and the impact is primarily a confidentiality of data that may reside in the browser process memory.
OpenCVE Enrichment
Debian DLA
Debian DSA