Impact
The flaw stems from an uninitialized GPU resource in Google Chrome that, when a malicious HTML page is loaded, permits a compromised renderer process to read memory beyond the intended sandbox boundaries. This can lead to the disclosure of sensitive information from the renderer process or neighboring processes; the vulnerability does not alter data integrity or system availability. The weakness is classified as CWE-908, an uninitialized resource problem.
Affected Systems
Google Chrome releases older than version 152.0.7977.65 running on desktop platforms are vulnerable. The issue affects all desktop builds of the browser because the uninitialized GPU handling occurs in the standard rendering pipeline regardless of the specific OS.
Risk and Exploitability
The vulnerability carries a CVSS score of 3.4, indicating low overall severity, and its EPSS score is < 1%, meaning the likelihood of exploitation is very small. It is not listed in the CISA KEV catalog. Exploitation requires that the attacker already has control of the renderer process—typically through a malicious web page. Once renderer control is achieved, the attacker can read memory outside the renderer sandbox, potentially exposing confidential data. No direct denial of service or code‑execution capability is described, and the impact is limited to memory disclosure.
OpenCVE Enrichment
Debian DLA
Debian DSA