Impact
An uninitialized variable in Skia used by Google Chrome before version 150.0.7871.182 allows a remote attacker who has already compromised the renderer process to read and leak cross‑origin data through a crafted HTML page. Use of Uninitialized Variable (CWE‑457) and is that confidential data from other origins may be exposed to the attacker, compromising user privacy and potentially violating data protection regulations. Based on the description, the attacker would need to have already compromised the renderer process, as this condition is required before the uninitialized variable can be exploited.
Affected Systems
The vulnerability affects all installations of Google Chrome (desktop) that have not been updated to version 150.0.7871.182 or later. Specifically, the stable channel update released in July 2026 addresses this issue.
Risk and Exploitability
The EPSS score is below 1%, indicating a low probability of exploitation. The CVSS score of 3.1 indicates low severity. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that exploitation requires the attacker to already have privileges to compromise the renderer process, which would typically involve delivering a malicious HTML payload or leveraging another vulnerability to gain renderer control. Once the renderer is compromised, the attacker can read memory that was not properly initialized and exfiltrate cross‑origin data. While the likelihood of exploitation remains low, the potential impact on confidentiality is high.
OpenCVE Enrichment
Debian DLA
Debian DSA