Impact
An uninitialized variable in Google Chrome's GPU handling allows a remote attacker that has already compromised the renderer process to read potentially sensitive data from memory. This vulnerability enables information disclosure by extracting data stored in process memory, raising confidentiality concerns. The weakness is a classic case of uninitialized variable.
Affected Systems
The flaw affects Google Chrome versions prior to 150.0.7871.47 on all operating systems where GPU acceleration is used. Users browsing the installation are at risk until the vendor releases a fixed build.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as Medium. The EPSS metric is not available, and the issue is not listed in CISA KEV. Exploitation requires prior compromise of the renderer process, which could be achieved via malicious web content or a local exploit, making it less likely for casual attackers. Nonetheless, once the renderer is compromised, the attacker can read arbitrary memory and potentially leak credentials or other sensitive data. Given its Medium severity and the need for a preexisting compromise to exploit, organizations should consider it a low- to moderate-risk factor, especially if users run Chrome on systems with strong sandboxing and GPU security mitigations.
OpenCVE Enrichment
Debian DLA
Debian DSA