Impact
An uninitialized GPU resource in Google Chrome prior to version 152.0.7977.65 permits a remote attacker who has already compromised the renderer process to read data belonging to other web origins through a specially crafted HTML page. The flaw is a form of improper resource initialization (CWE‑908) that can leak confidential content from sandboxed renderer processes.
Affected Systems
All installations of Google Chrome before update 152.0.7977.65 are vulnerable, regardless of operating system, as the issue resides in the GPU handling code within the renderer process of the Chrome browser.
Risk and Exploitability
The flaw carries a Chromium‑rated high severity, but the CVSS score of 3.1 indicates a low overall severity. Its EPSS score is less than 1%, suggesting a very low probability of exploitation. An attacker must first succeed in compromising the renderer process, after which they can potentially exfiltrate cross‑origin data. Although the risk of initial compromise depends on other software bugs, once achieved the data leakage could occur without further action by the attacker.
OpenCVE Enrichment
Debian DLA
Debian DSA