Impact
A flaw in Chrome’s handling of GPU resources before version 151.0.7922.169 permitted a renderer process that had already been compromised to read memory outside its sandbox. The vulnerability relies on the use of an uninitialized GPU resource, which effectively leaks confidential data that belongs to other processes or system memory. Attackers exploiting this flaw could gain access to sensitive information but would need the renderer process to be already compromised, limiting the attack surface to browsers that have been infiltrated by malicious code.
Affected Systems
Google Chrome, any desktop build older than 151.0.7922.169. The issue is tied to the GPU component within the renderer process; any user running an affected version of the stable channel on Windows, macOS, Linux, or Chrome OS is at risk.
Risk and Exploitability
The primary vector inferred is a crafted HTML page that triggers the GPU path after the renderer process has been hijacked. The CVSS score is reported as High by Chromium, and no exploit probability score or KEV listing is available, indicating that, while the high severity suggests developers should act quickly, there are no confirmed public exploits. Because the flaw requires a pre‑existing compromise of the renderer, attackers would first need to breach Chrome via another vulnerability or malicious plug‑in before utilizing this memory disclosure. Nonetheless, the confidentiality impact is severe when the assumption of a compromised renderer holds.
OpenCVE Enrichment