Impact
An uninitialized use in ANGLE, the graphics library used by Google Chrome, enables a remote attacker to cause the browser to read uninitialized memory when a specially crafted HTML page is loaded. This flaw, classified as CWE‑457, can expose data belonging to other origins, leading to accidental disclosure of sensitive information across site boundaries.
Affected Systems
Google Chrome installations older than version 150.0.7871.46 on any platform are susceptible. Versions 150.0.7871.46 and later include the patch that resolves the uninitialized use in ANGLE.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate risk, and the EPSS score of less than 1 % indicates The vulnerability is not listed in the CISA KEV catalog, signifying no known public exploits. A remote attacker would need to serve a malicious HTML page that triggers the ANGLE library to read uninitialized memory, thereby leaking cross‑origin data when a user visits in Chrome.
OpenCVE Enrichment
Debian DLA
Debian DSA