Impact
In Chrome versions before 151.0.7922.72 the Skia graphics library can use memory that has not been properly initialized. A crafted HTML page loaded by Chrome can trigger this uninitialized use and expose data that originated from other web origins, compromising confidentiality but not allowing code execution.
Affected Systems
Google Chrome on desktop systems running versions earlier than 151.0.7922.72 are affected. This applies to all users who have not updated to the latest stable channel.
Risk and Exploitability
The CVSS score of 4.3 denotes a medium severity vulnerability. The EPSS score of less than 1 % indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to serve a malicious web page that exploits the Skia bug; successful exploitation could leak cross‑origin information but would not provide broader system access.
OpenCVE Enrichment
Debian DLA
Debian DSA