Impact
An uninitialized resource in Chrome's Media code allows a remote attacker who has already compromised the renderer process to read memory outside the sandbox through a crafted HTML page. The flaw can expose arbitrary memory contents, potentially leaking sensitive data such as credentials, cryptographic material, or other private application data, thereby undermining confidentiality. The impact is limited to the renderer process but can be leveraged to compromise the broader system if other components interact with the leaked data. The vulnerability is classified with medium severity by Chromium, indicating a noticeable but not critical risk if mitigated promptly.
Affected Systems
The issue affects Google Chrome on desktop platforms running any version earlier than 153.0.8010.36. Versions 153.0.8010.36 and newer contain the fix that was deployed in the stable channel update announced in September 2026.
Risk and Exploitability
The exploit requires a remote attacker to supply a specifically crafted HTML page that is processed by a renderer process that has been compromised. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The low security severity indicated by a CVSS score of 3.4 and the fact that the attacker must already have bypassed the renderer sandbox lower its overall risk profile, but the memory read could still be used for sensitive information theft or as a stepping stone to further attacks. The attack vector is remote via web content, and exploitation requires the attacker’s code to run with renderer privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA