Impact
This flaw arises from an uninitialized video resource in Chrome’s rendering engine, allowing a crafted HTML page to cause the browser to read memory inside its sandbox. The vulnerability is rooted in a CWE‑908 issue, where uninitialized data is accessed, and can expose sensitive in‑process information to a remote attacker.
Affected Systems
The issue affects all Chrome releases prior to 152.0.7977.65 for all supported operating systems, as specified by Google. Upgrading to version 152.0.7977.65 or later resolves the problem.
Risk and Exploitability
While the exploit requires a specially crafted web page, it can be delivered remotely via a standard HTTP or HTTPS request. The CVSS score of 6.5 and the EPSS score of < 1% indicate a medium severity with a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. This flaw still exposes a non‑trivial confidentiality risk by allowing an attacker to read arbitrary memory within the browser process, potentially leaking secrets or facilitating further attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA