Impact
Uninitialized memory use in Skia, the graphics library in Google Chrome, may allow a remote attacker who has already compromised the renderer process to read memory containing data from another origin, enabling a leak of cross‑origin information. This is an information‑disclosure vulnerability, corresponding to CWE-457 for uninitialized variables.
Affected Systems
Google Chrome browsers running any version prior to 151.0.7922.109 are affected. Versions before the specified release may still be vulnerable to the described memory‑use bug.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity, but on Chromium’s own scale the vulnerability is classified as high. Exploitation requires an attacker to control the renderer process, which is a non‑local attack vector that could be achieved if that process is compromised. No public exploit code or EPSS score is listed, and it is not in the CISA KEV catalog. Nonetheless, the combination of internal high severity and the potential for data leakage warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA