Impact
Uninitialized resource in ANGLE allows a remote attacker to bypass the browser’s same-origin policy using a specially crafted HTML page. This flaw, classified as CWE-908 and CWE-824, grants privileged access to web content that should be restricted, potentially enabling data leakage or execution of malicious scripts. The CVSS score of 4.3 reflects the medium severity of this vulnerability as evaluated by the Chromium security team.
Affected Systems
All Google Chrome installations older than version 152.0.7977.65 are affected, regardless of the operating system, because the issue resides in the ANGLE graphics component bundled with the browser.
Risk and Exploitability
The EPSS score is less than 1 % and the CVSS score is 4.3, indicating a medium severity but low probability of mass exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote, web-based one where an attacker serves a malicious HTML page that triggers the uninitialized resource, potentially leading to data breaches or the execution of arbitrary code within the browser context.
OpenCVE Enrichment
Debian DLA
Debian DSA