Impact
The vulnerability is an uninitialized use in the WebCodecs API within Google Chrome that can lead to the exposure of sensitive data from the browser process's memory. This flaw falls under the CWE-457 classification, which describes the use of a variable before it has been initialized, permitting an attacker to read unintended memory contents. The impact is limited to leakage of potentially sensitive information rather than arbitrary code execution or denial of service.
Affected Systems
Google Chrome is affected, specifically all releases prior to version 148.0.7778.96. Users running an older Chrome browser are at risk if they access webpages that include WebCodecs components.
Risk and Exploitability
The CVE provides no EPSS score, and it is not listed in the CISA KEV catalog, indicating that there are currently no known widespread exploits. However, the attack can be launched remotely by a malicious or compromised web page, which suggests that a user’s interaction with such content is a prerequisite. Because the flaw permits the reading of memory, the CVSS score of 6.5 classifies the severity as Medium and the likelihood is considered low to moderate in the absence of publicly known exploits.
OpenCVE Enrichment
Debian DSA