Impact
A flaw in Chrome’s handling of GPU resources before version 151.0.7922.169 permitted a renderer process that had already been compromised to read memory outside its sandbox. The vulnerability relies on the use of an uninitialized GPU resource, which effectively leaks confidential data that belongs to other processes or system memory. Attackers exploiting this flaw could gain access to sensitive information but would need the renderer process to be already compromised, limiting the attack surface to browsers that have been infiltrated by malicious code.
Affected Systems
Google Chrome, any desktop build older than 151.0.7922.169. The issue is tied to the GPU component within the renderer process; any user running an affected version of the stable channel on Windows, macOS, Linux, or Chrome OS is at risk.
Risk and Exploitability
Based on the description, the likely attack vector is a crafted HTML page that engages the GPU in a renderer process that has already been compromised, enabling an out‑of‑sandbox memory read. The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1 % shows a very low probability of exploitation at the time of analysis. Because the flaw requires that the renderer process has been hijacked beforehand, attackers would need to first break into Chrome via another vulnerability or malicious extension before exploiting this memory disclosure. Although the confidentiality impact is limited to a compromised renderer, the overall risk remains low, and there are currently no known public exploits or KEV record.
OpenCVE Enrichment
Debian DLA
Debian DSA