Impact
An uninitialized use flaw in the WebXR component of Google Chrome on Android allows a remote attacker to read potentially sensitive information from process memory via a crafted HTML page. This flaw is an instance of CWE-457. The vulnerability results from the browser using data that has not been properly initialized, enabling disclosure of information that should otherwise be protected. This flaw can compromise the confidentiality of data stored in the browser process.
Affected Systems
Google Chrome for Android versions earlier than 150.0.7871.47 are affected. Any device running a pre‑150.0.7871.47 build is susceptible when a user loads a malicious WebXR‑enabled page.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium severity. The EPSS score is <1% and it is not listed in the CISA KEV catalog. The likely attack vector is remote: an attacker serves a crafted HTML page that activates WebXR, triggering a read of uninitialized memory. Exploitation requires the victim to load the page, so user interaction is needed. The potential impact is the exposure of confidential data from the Chrome process, but the attack does not provide direct code execution or broader system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA