Impact
Uninitialized resources in the Dawn graphics driver of Google Chrome prior to version 152.0.7977.65 let a remote attacker craft an HTML document that could read sensitive data from memory that resides inside the sandbox. The flaw is a misuse of uninitialized memory (CWE‑908) and can lead to accidental disclosure of user data or potentially facilitate further exploitation. Confidentiality is at risk if the memory contains sensitive material.
Affected Systems
The vulnerability affects Google Chrome browsers running versions before 152.0.7977.65. Systems using any earlier Chrome build are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score is <1%, indicating a very low exploitation probability. The flaw can be triggered by a remote web page loaded into Chrome, allowing an attacker to read memory that resides inside the sandbox. It does not require local privileges, and the primary impact is potential disclosure of sensitive data.
OpenCVE Enrichment
Debian DLA
Debian DSA