Impact
An uninitialized resource within the ANGLE graphics component of Google Chrome allowed a remote attacker to obtain cross‑origin data when a victim visited a crafted HTML page. This flaw exposes the victim's private data to an attacker and is rated low severity based on the CVSS score of 4.3, although Chromium classified it as high severity. The weakness arises from improper initialization of ANGLE resources, corresponding to CWE‑908.
Affected Systems
Google Chrome browsers running versions prior to 152.0.7977.65 are affected. The vulnerability applies to all platforms where ANGLE is normally used for rendering GPU‑accelerated content.
Risk and Exploitability
The CVSS score of 4.3 indicates a low potential impact. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote via a maliciously crafted HTML page that a user must load; no local privilege escalation or code execution is required. Once the victim loads the page, cross‑origin data can be read by the attacker.
OpenCVE Enrichment
Debian DLA
Debian DSA