Impact
The flaw is an uninitialized use of a codec component in Google Chrome on Windows that can cause sensitive data to be read from process memory. A crafted HTML page accessed by a remote attacker can trigger the code that reads uninitialized memory, potentially leaking confidential information from the browser process. This vulnerability is identified as CWE‑457 and directly affects the confidentiality of the user's data.
Affected Systems
Google Chrome users on Windows with versions earlier than 150.0.7871.47 are affected. The vulnerability manifests when a user loads a malicious HTML page in Chrome; no other operating systems or browsers are listed as affected.
Risk and Exploitability
The flaw can be exploited remotely by delivering a crafted HTML page to a victim’s browser. Because the attacker must first entice the victim to open the page, the likelihood of widespread attacks is low, as reflected by an EPSS score of less than 1 %. The CVSS score of 6.5 indicates a medium impact, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed public exploits to date.
OpenCVE Enrichment
Debian DLA
Debian DSA