Impact
An uninitialized variable in the Dawn rendering engine of Google Chrome on ChromeOS allows a remote attacker, via a crafted HTML page, to read data from the browser's process memory. The flaw, classified as CWE-457, results in the disclosure of potentially sensitive information without requiring authentication, leading to confidentiality loss.
Affected Systems
Google Chrome on ChromeOS versions earlier than 150.0.7871.46 are affected. Devices running these builds remain vulnerable until they receive the patched release from Google.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 and an EPSS score of less than 1%. This indicates a medium severity but a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to deliver and render malicious HTML to potentially glean sensitive data.
OpenCVE Enrichment
Debian DLA
Debian DSA