Impact
An uninitialized resource in Chrome’s ANGLE graphics layer permits a malicious web page to read data that should be confined to a separate origin, thereby exposing private or sensitive information to an attacker. The weakness lies in insufficient initialisation before buffer utilisation, classified as CWE‑908. The vulnerability’s severity is tagged as medium by Chromium security, indicating a non‑critical but still acceptable risk if exploited.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 are affected. A malicious web page can trigger this issue when loaded by a user.
Risk and Exploitability
The flaw can be triggered via a carefully structured HTML page served from a remote host, suggesting a remote exploitation path. No evidence of a public exploit is available, and EPSS is < 1%, so the likelihood of immediate exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog, reducing urgency but still warranting patching as soon as possible. The CVSS score of 6.5 indicates a medium severity.
OpenCVE Enrichment
Debian DLA
Debian DSA