Impact
This vulnerability is a CWE-457 (Uninitialized Variable) flaw caused by an uninitialized variable in the V8 engine of Google Chrome. It also involves a CWE-824 weakness, both allowing an attacker to retrieve sensitive data from process memory via a crafted HTML page. An attacker can trigger this flaw by loading a crafted HTML page, causing the browser to read data from process memory that has not been properly set. The result is that sensitive information can leak from the Chrome process, compromising the confidentiality of the user’s data without requiring elevated privileges.
Affected Systems
The affected product is Google Chrome. Versions prior to 150.0.7871.125 are vulnerable. Any install of Chrome that has not yet been updated to 150.0.7871.125 or later is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate level of severity. The EPSS score shows an exploitation probability of less than 1%, meaning that the likelihood of attack at this time is very low, and it is not listed in CISA's KEV catalog. The attack vector is inferred to be remote: a crafted web page can trigger the flaw from a remote browser instance. Because the flaw depends on reading uninitialized memory, an attacker gains only data that happens to reside in memory at the time; however, the potential confidentiality impact remains significant.
OpenCVE Enrichment
Debian DLA
Debian DSA