Impact
The vulnerability allows a crafted web page to trigger an out-of-bounds read inside the GPU driver of Google Chrome on Android, exposing memory contents that belong to the sandboxed process. This does not provide code execution or write capabilities but can leak sensitive data from the process address space. The weakness is a classic out-of-bounds read condition (CWE-125).
Affected Systems
Google Chrome running on Android devices with a version earlier than 152.0.7977.65 is impacted. The issue is specific to Chrome's GPU handling on Android and does not affect non-Android builds or later versions of the browser.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score is less than 1%, signaling a low likelihood of exploitation in the near term, and the flaw is not listed in CISA’s KEV catalog, so no publicly known exploits exist yet. The vulnerability is triggered by a crafted HTML page, meaning a remote attacker can entice a user to visit a malicious site to activate the out-of-bounds read and leak memory data from Chrome’s sandboxed process.
OpenCVE Enrichment
Debian DLA
Debian DSA