Impact
Uninitialized use of GPU memory in Google Chrome for Android allows an attacker who has already compromised the renderer process to read sensitive data from process memory. The flaw is described as a high‑severity vulnerability by Chromium and is identified as CWE‑457 and CWE‑824. By delivering a crafted HTML page that triggers GPU activity, the compromised renderer can expose contents of its memory, potentially leaking user information that was accessed by that renderer.
Affected Systems
All Android builds running Google Chrome prior to version 151.0.7922.109 are affected. This includes every device that has not yet applied the stable‑channel update to 151.0.7922.109.
Risk and Exploitability
The CVSS score is 5.3, representing a medium severity flaw. The EPSS score is 0.00288 (<1%), indicating a very low exploitation probability. The issue is not listed in the CISA KEV catalog. The attack requires the renderer process to already be compromised, so the vulnerability cannot be used to elevate privileges beyond that process, but it does enable a partial confidentiality breach of data held in renderer memory.
OpenCVE Enrichment
Debian DLA
Debian DSA