Impact
The vulnerability is an uninitialized use of a variable within ANGLE, Chrome's graphics abstraction layer. If the renderer process is already compromised, a crafted HTML page can cause the browser to read from memory that has not been initialized. This flaw can lead to a sandbox escape, allowing the attacker to execute code outside the renderer sandbox and potentially compromise the host system.
Affected Systems
Google Chrome is affected. The flaw resides in the renderer process that interacts with ANGLE. Version information is not explicitly provided by the CNA data, but the reference indicates that Chrome versions prior to 150.0.7871.46 are vulnerable. The vulnerability applies to all platforms supported by Chrome, as no platform restrictions are noted.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. The EPSS score is less than 1%, showing a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Attackers would first need to compromise the renderer process, for example through malicious web content, before triggering the uninitialized use. Once the renderer is compromised, the flaw can be exploited to escape the browser sandbox and potentially execute code on the host.
OpenCVE Enrichment
Debian DLA
Debian DSA