Impact
Uninitialized memory use in Chrome’s media codecs allows a remote attacker to read portions of the browser’s process memory through a crafted HTML page. This flaw is tied to improper initialization of data buffers in the codec subsystem, which leads to a potential confidentiality breach when malicious content is rendered in the browser.
Affected Systems
Google Chrome for Windows users running any version prior to 150.0.7871.47 on the stable channel are impacted. The issue surfaces in all builds before the referenced patch and does not affect other platforms or product versions according to the current advisory.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as Medium severity. The EPSS score is below 1%, indicating a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is a malicious web page served to a victim, where the browser renders crafted media or script content. Once the user visits or renders such content, the attacker can obtain sensitive memory data with minimal technical effort. The limited attack surface and ease of exploitation raise concerns for organizations that serve untrusted web content or allow users to browse freely.
OpenCVE Enrichment
Debian DLA
Debian DSA