Impact
Uninitialized use of a value in the Skia graphics library of Google Chrome can allow a remote attacker to read potentially sensitive data from the browser, a classic use‑of‑uninitialized‑value (CWE‑457) vulnerability. The flaw also maps to CWE‑824, indicating a related data‑leak weakness. The impact is restricted to confidentiality; there is no evidence of arbitrary code execution or denial of service.
Affected Systems
This vulnerability affects desktop installations of Google Chrome versions prior to 150.0.7871.125. Versions 150.0.7871.125 and later contain the fix. The issue is limited to the Skia rendering engine and does not affect other components of Chrome.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high risk. The EPSS score of less than 1 % reflects a low but non‑zero exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, so no known active exploits are reported. The likely attack vector is an active network‑based scenario where the attacker hosts a malicious web page that exploits the uninitialized use in Skia during rendering.
OpenCVE Enrichment
Debian DLA
Debian DSA