Impact
An uninitialized use in the media handling component of Google Chrome enables a remote attacker who has already gained code execution inside the renderer process to read arbitrary data from the renderer’s memory by serving a crafted HTML page. This results in a potential disclosure of sensitive information held in process memory and is classified as a medium‑severity vulnerability per Chromium’s security score, identified by CWE‑457.
Affected Systems
All installations of Google Chrome older than version 150.0.7871.47 are affected. The flaw resides in the renderer process that handles media content; the process is sandboxed, but if the sandbox is breached, the vulnerability can be triggered.
Risk and Exploitability
The CVSS score of 5.3 indicates medium impact. No EPSS data exist, and the vulnerability is not cataloged in the CISA KEV list. Exploitation requires prior compromise of the renderer process. Once that condition is met, a malicious web page can activate the uninitialized read and leak memory contents, affecting confidentiality but not granting full system control.
OpenCVE Enrichment
Debian DLA
Debian DSA