Impact
Uninitialized use in the ANGLE graphics library within Google Chrome allows a remote attacker to read potentially sensitive data from the process's memory when a user visits or interacts with a crafted HTML page. This flaw results in the disclosure of information rather than enabling code execution or denial of service, and the Chromium security team rates its severity as low.
Affected Systems
Google Chrome versions prior to 150.0.7871.47 are affected. All releases older than 150.0.7871.47, including the 150.0.7871.46 build, contain the uninitialized use bug in ANGLE.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the weakness by hosting a malicious web page that triggers the ANGLE path. The likely attack vector is a remote web page served over HTTP or HTTPS. The CVSS score of 6.5 indicates a medium severity vulnerability, and because the flaw only allows memory disclosure, a high-impact compromise is not possible. However, any leaked data from memory could include credentials or other secrets. The overall risk remains low given the current exploitation likelihood and the limited impact scope.
OpenCVE Enrichment
Debian DLA
Debian DSA