Impact
A flaw in Google Chrome’s GPU handling causes an uninitialized use of memory that lets an attacker who has control over the renderer process leak cross‑origin data. The vulnerability is a classic instance of CWE‑457, where an uninitialized variable is used, allowing unintended data exposure. The primary impact is the accidental disclosure of data that should be isolated from the attacker. The vulnerability can be exploited through a crafted web page or malicious content that runs in the compromised renderer, which the attacker must first gain access to. No additional conditions beyond renderer compromise are required.
Affected Systems
Any installation of Google Chrome older than version 148.0.7778.96 is vulnerable. This includes all stable channel releases before the fixed version and therefore applies to users not yet updated on the current month’s stable release.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity vulnerability. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation. An attacker who has compromised the renderer could read cross‑origin data but cannot execute code or modify the system. The risk is moderate, but because the flaw enables data leakage, patching is recommended.
OpenCVE Enrichment
Debian DSA