Impact
An uninitialized memory read in the WebCodecs component of Google Chrome allows a remote attacker to read data that has not been properly initialized. The data obtained can include sensitive information such as encryption keys or other confidential tokens, thus compromising confidentiality. This vulnerability is rated medium in severity by CVSS, reflecting its potential to expose secrets but not granting full control over the system.
Affected Systems
All users running Google Chrome before version 147.0.7727.55 on Windows, macOS, and Linux are affected. The vulnerability resides in the browser core and is triggered when a crafted HTML page is loaded in the browser, regardless of the underlying operating system.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate risk, while an EPSS score of less than 1 % suggests the likelihood of widespread exploitation is low. The vulnerability is not listed in the CISA KEV catalog. The most probable attack vector is remote, requiring an attacker‑controlled web page that triggers the uninitialized memory read. No additional prerequisites are described, implying that the exploit can be launched from a simple web page in the victim’s browser.
OpenCVE Enrichment
Debian DSA