Impact
Uninitialized data in the GPU driver caused by a flaw in Chrome on Android prior to version 148.0.7778.96 could be exploited by an attacker who has already compromised the renderer process. By serving a specially crafted HTML page the attacker can read sensitive information from memory, potentially exposing credentials, keys or other confidential data. The flaw is a classic uninitialized use, designated CWE-457. The CVSS score of 5.3 indicates medium severity.
Affected Systems
The vulnerability affects Google Chrome on Android devices running any version before 148.0.7778.96. It is limited to the Chrome browser component and does not extend to other Google or Android system processes.
Risk and Exploitability
While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the requirement that the renderer process be already compromised reduces the overall risk to environments where such compromise is unlikely. The attack vector depends on the attacker being able to load a malicious web page in a compromised renderer, which would typically require initial local or remote exploitation of Chrome. Nevertheless, any system exposed to untrusted web content must upgrade promptly to the fixed release to eliminate the memory disclosure risk.
OpenCVE Enrichment