Impact
An uninitialized resource in the ANGLE graphics engine of Google Chrome on Windows can be triggered by a remote attacker via a specially crafted HTML page. The flaw allows the attacker to read data that is normally isolated per origin, effectively leaking cross‑origin content. The weakness is an uninitialized resource (CWE-908) and does not provide arbitrary code execution, but it compromises the confidentiality of web resources accessed by the browser.
Affected Systems
Google Chrome for Windows versions prior to 152.0.7977.65 are affected. No other browsers or operating systems were listed as impacted.
Risk and Exploitability
The vulnerability has a Chromium severity of Medium and a CVSS score of 6.5, and the EPSS score is < 1%. It is not listed in the CISA KEV catalog. The likely attack vector is remote via a malicious HTML page served over the network to a user’s machine. Exploitation requires the user to load the crafted page in Chrome, after which the attacker can read cross‑origin data. The risk is moderate, with a potential impact on data confidentiality but no direct code execution or denial of service. Timely patching reduces the window of opportunity for such data theft.
OpenCVE Enrichment
Debian DLA
Debian DSA