Impact
An uninitialized variable in the Skia graphics library allows code that runs in the renderer process to read memory that it should not access. The flaw is a classic use‑of‑uninitialized‑memory weakness (CWE‑457) and can lead to leaking sensitive data from process memory. The vulnerability is not exploitable by a normal web page alone; an attacker must first gain control of the renderer process and then serve a crafted HTML page that triggers the uninitialized read. The potential impact is the disclosure of private information that resides in the renderer’s address space, such as passwords, authentication tokens, or other confidential data.
Affected Systems
Google Chrome versions earlier than 150.0.7871.47 are affected. The flaw resides in the Skia component of Chrome, the cross‑platform graphics library used by the renderer. All desktop releases that include this version are vulnerable until patched.
Risk and Exploitability
The vulnerability carries a Chromium severity rating of Medium, and its CVSS score is 5.3. No EPSS data is available, and the flaw is not listed in the CISA KEV catalog, indicating that no widespread exploitation has been reported. The attack requires the attacker to have already compromised the renderer process, a non‑trivial prerequisite, so the likelihood of exploitation remains moderate but not negligible. In practice, the flaw poses an information‑disclosure risk to users who run untrusted web content in Chrome before the update.
OpenCVE Enrichment
Debian DLA
Debian DSA