Impact
An uninitialized resource in ANGLE inside Google Chrome versions prior to 152.0.7977.65 allows a remote attacker who has already compromised the renderer process to read memory outside the sandbox, using a crafted HTML page. This flaw results in memory disclosure and could expose sensitive data that is not protected by the renderer sandbox. The vulnerability is categorized as a medium severity issue in Chromium security terms.
Affected Systems
The affected product is Google Chrome on desktop platforms. Versions before 152.0.7977.65, which are actively delivered to users via the stable channel, are susceptible. Any environment that delivers the pre‑152 build without immediate patching will be exposed.
Risk and Exploitability
The requirement of renderer process compromise represents a prerequisite for exploitation; an attacker must first bypass regular content sandbox checks or achieve code execution in the renderer. Once that condition is met, the memory leak is straightforward to trigger. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no current public exploitation evidence. The CVSS score is 6.5, reflecting a medium severity that aligns with the Chromium severity assessment, and indicates that mitigation should be addressed promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA