Impact
In Google Chrome versions before 151.0.7922.72, an improper WebGL implementation can be leveraged by a remote attacker to read the browser’s process memory through a crafted HTML page, potentially exposing sensitive data. The flaw aligns with CWE-200, which concerns unauthorized disclosure of information.
Affected Systems
Google Chrome users running any release older than 151.0.7922.72 are affected. The vulnerability is specific to the WebGL component of the browser and does not impact other browsers or Chrome extensions.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of < 1% shows the model currently estimates a low exploit probability, and the vulnerability is not listed in the CISA KEV catalog, so no confirmed active exploitation is known. Nevertheless, the attack vector is remote and requires only that a user load a malicious web page, so the risk remains realistic for general users if no mitigation is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA