Impact
An uninitialized resource in the Skia graphics library used by Google Chrome allows a remote attacker to read memory within the browser sandbox by serving a crafted HTML page. The vulnerability exploits improper initialization to expose internal data, potentially leaking sensitive information to the attacker.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected. Users running any earlier stable channel of Chrome are vulnerable; upgrading to 152.0.7977.65 or later mitigates the issue.
Risk and Exploitability
The Chromium security team rated this issue as low severity, the EPSS score is unavailable, and it is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The attack vector requires remote delivery of a malicious HTML page that is opened by a user with Chrome running, and the exploit would read memory inside the sandbox rather than achieving code execution.
OpenCVE Enrichment