Impact
The vulnerability is an uninitialized use bug in the HTML5 Canvas implementation that allows a remote user to read sensitive data from Chrome process memory when a crafted HTML page is loaded. The flaw results in an information‑disclosure outcome; the attacker can obtain data that the browser has in memory. The weakness is a classic uninitialized local variable error (CWE‑457).
Affected Systems
All Android installations of Google Chrome older than 150.0.7871.47 are vulnerable. This includes any device running the stable channel of Chrome for Android for which the version number has not been updated to 150.0.7871.47 or later.
Risk and Exploitability
Chromium assigns a medium severity rating to this issue based on the CVSS score of 6.5. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the victim to visit a malicious web page; the privilege scope is confined to sensitive data stored in the browser’s process memory. Given the medium CVSS score but low exploitation probability, the risk is moderate but still actionable.
OpenCVE Enrichment
Debian DLA
Debian DSA