Impact
An uninitialized resource in the ANGLE graphics subsystem of Google Chrome can be exploited by a remote attacker to read cross‑origin data. A maliciously crafted HTML page triggers the flaw, allowing the attacker to bypass the browser's same‑origin policy and obtain information that should be protected. The problem is a type of CWE‑908 vulnerability that exposes data through improper resource handling.
Affected Systems
Google Chrome installations running any version older than 152.0.7977.65 are affected. The issue exists in all desktop builds of the stable channel before that release.
Risk and Exploitability
The vulnerability is remote and requires only an attacker‑controlled HTML page to be loaded in the victim’s browser, meaning that compromised or malicious websites can trigger it. The EPSS score of 0.00244 indicates a very low exploitation probability, and the CVSS score of 4.3 places the flaw in the low to medium severity range. Although it is not currently listed in CISA’s KEV catalog, the flaw allows cross‑origin data leakage which could expose sensitive information. Users should be aware that any web page opened in the affected browser may compromise the confidentiality of data that should be protected by the same‑origin policy.
OpenCVE Enrichment
Debian DLA
Debian DSA