Impact
This vulnerability stems from an uninitialized use in the GPU component of Google Chrome. An attacker who first compromises the renderer process can craft a malicious HTML page that causes the GPU to read memory that has not been properly initialized, potentially exposing sensitive data. The weakness is categorized as CWE-457, and the Chromium team rates its severity as Medium.
Affected Systems
Google Chrome versions prior to 148.0.7778.96 on the stable channel are affected. The issue appears when the application loads content through the renderer process on a desktop system and utilizes GPU features.
Risk and Exploitability
Exploitation requires a renderer compromise, which could be achieved through malicious web content. The lack of an EPSS score and absence from the CISA KEV catalog suggest limited public exploitation activity. The CVSS score is 5.3, but the Chromium severity is Medium, indicating a moderate risk of data leakage without full remote code execution.
OpenCVE Enrichment
Debian DSA