Impact
An uninitialized GPU resource in Google Chrome on Android allows a remote attacker to read memory outside the sandbox by loading a crafted HTML page. The vulnerability exploits the use of an uninitialized resource (CWE‑908) and can expose confidential data, although it does not provide code execution or denial of service. The Chromium severity is low, indicating the impact is limited to confidentiality loss rather than a full system compromise.
Affected Systems
Affected are users running Google Chrome on Android devices with versions earlier than 152.0.7977.65. The flaw resides in the GPU component of the browser and is specific to the Android operating system. Devices with Chrome 151 or lower or earlier builds are susceptible until they upgrade.
Risk and Exploitability
The vulnerability can be exploited remotely by delivering a malicious web page that references the GPU resource; the attack vector is thus a crafted HTML page viewed in the browser. No public exploits are known and the EPSS score is < 1%, so the likelihood of exploitation remains uncertain but is considered low at this time. The flaw is not listed in the CISA KEV catalog, reflecting that it does not pose an immediate exploited risk. Given the CVSS score of 4.3, which indicates a low severity rating, and absence of active exploitation, the risk to typical end users is minimal, but upgrading mitigates the vulnerability immediately.
OpenCVE Enrichment
Debian DLA
Debian DSA