Impact
An uninitialized resource in ANGLE within Google Chrome permits a remote attacker to read memory beyond the sandbox by loading a specially crafted HTML page. The vulnerability enables confidential data leakage, exposing information stored in the victim’s process memory. It does not provide direct code execution or denial‑of‑service functionality.
Affected Systems
All installations of Google Chrome older than version 152.0.7977.65 on desktop platforms are affected. This includes the stable channel released before August 2026. The update that addresses the flaw is Chrome 152.0.7977.65, available through the official Chrome updates.
Risk and Exploitability
The flaw is exploitable from a web page, so an attacker only needs a victim to visit a malicious site or open a manipulated document. The confidentiality impact is moderate to high because attackers can read sensitive data. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating it is not a known widespread exploitation yet. However, the vulnerability’s medium severity rating by Chromium and a CVSS score of 6.5 suggests a meaningful risk for users who frequently browse untrusted content.
OpenCVE Enrichment
Debian DLA
Debian DSA