Impact
The vulnerability arises from an uninitialized GPU resource in Chrome before version 152.0.7977.65, a CWE-908 flaw. A remote attacker who has already compromised the renderer process could exploit this flaw to read arbitrary memory outside the sandbox by serving a specially crafted HTML page. This memory disclosure could expose sensitive information or enable further escalation depending on the attacker's goals.
Affected Systems
Affected products include Google Chrome versions earlier than 152.0.7977.65 on all desktop platforms. Users of the stable channel prior to that build are vulnerable until they upgrade to the patched release.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the vulnerability is not listed in CISA KEV. Exploitation requires a renderer process compromise and a crafted HTML page, limiting the attack surface. The EPSS score of <1% indicates a very low exploitation probability. The low CVSS score and lack of public exploits suggest a moderate risk mainly for targeted attackers.
OpenCVE Enrichment
Debian DLA
Debian DSA