Impact
An uninitialized memory use flaw in Chrome’s ANGLE graphics library can cause the browser to expose data that should not be accessible from other origins. When a malicious web page containing a specially crafted payload is rendered, it may leak information from documents or resources that belong to a different origin, effectively bypassing the same‑origin policy. The flaw stems from memory that was allocated but not properly initialized, allowing the attacker to read residual data. The vulnerability is designated as a High severity issue by the Chromium security team, relating to CWE‑457 (Use of Uninitialized Variable) and CWE‑824 (Use of Null Pointer). Affected Systems: Google Chrome versions older than 151.0.7922.72 on all desktop operating systems (Windows, macOS, Linux). The issue is present in the standard desktop builds that include the ANGLE rendering backend. Users who have yet to install the July 2026 stable channel update are susceptible.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 on Windows, macOS, and Linux desktop architectures are affected.
Risk and Exploitability
The CVSS score of 4.3 classifies the flaw as a moderate‑level risk. The EPSS value of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Remote exploitation requires an attacker to craft a malicious webpage that the victim visits; no privileged local access is necessary. The attack can lead to leakage of confidential browsing data but does not provide code execution or privilege escalation. Although the exploitation path is straightforward, the low incidence likelihood mitigates the overall threat.
OpenCVE Enrichment
Debian DLA
Debian DSA