Impact
An uninitialized memory read in the GamepadAPI of Google Chrome allows a remote attacker who has gained control over the renderer process to read data from process memory. The vulnerability surfaces when a crafted HTML page is served to the user, and the renderer process is already compromised. The flaw falls under CWE-457 and can cause leakage of sensitive information; however, Chromium classifies it as Low severity.
Affected Systems
All installations of Google Chrome prior to version 150.0.7871.47 are affected. Users on earlier stable releases are at risk until they upgrade to the patched build.
Risk and Exploitability
The flaw requires an attacker to first compromise the renderer process, typically achieved via malicious web content. While it does not lead to arbitrary code execution, the CVSS score of 6.5 indicates a medium severity that could result in partial data disclosure. There is no evidence of exploitation in the wild, and EPSS data is unavailable; the issue is not listed in CISA’s KEV catalog. The risk remains in environments where user browsers cannot be promptly updated or where renderer processes are given excessive privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA