Impact
The flaw originates from an uninitialized GPU resource that allows a remote attacker to craft an HTML page capable of reading memory inside Chrome's sandbox. The result is a confidentiality breach, potentially exposing sensitive data. The weakness is classified as CWE‑908.
Affected Systems
Google Chrome running on Android devices prior to version 152.0.7977.65 is affected. The issue appears in the stable channel of the browser. Users on older builds should upgrade to the latest release to get the fix.
Risk and Exploitability
Chromium rates the vulnerability as low severity with a CVSS score of 6.5, and an EPSS score of <1% indicates a low likelihood of exploitation. It is not listed in the CISA KEV catalog. Attackers would need to entice a user to a malicious web page that targets the GPU driver. The impact is limited to sandbox memory reads, but it still allows capture of potentially sensitive information.
OpenCVE Enrichment
Debian DLA
Debian DSA