Impact
A side‑channel information leakage in the GPU component of Google Chrome for Android allows a remote attacker to read confidential data from other origins by serving a specially crafted HTML page. The flaw can lead to unauthorized disclosure of cross‑origin content and is classified as CWE‑1300 and CWE‑205.
Affected Systems
Google Chrome on Android is affected. Versions prior to 151.0.7922.72 contain the vulnerability; all devices running the stable channel of Chrome with GPU support are at risk unless they update to the patched release.
Risk and Exploitability
The CVSS score of 4.3 classifies the flaw as medium severity, and the EPSS score of less than 1 % indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploits. Exploitation requires a user to visit a malicious web page in the browser, after which an attacker can read sensitive information from another origin through the GPU side‑channel.
OpenCVE Enrichment
Debian DLA
Debian DSA