Impact
An uninitialized resource in Chrome's codec implementation allows a remote attacker to read memory inside the browser sandbox. The flaw, classified as CWE‑908 and CWE‑824, could expose sensitive data or enable further exploitation by leaking information that is normally protected by the sandbox.
Affected Systems
Google Chrome browsers with version numbers earlier than 153.0.8010.36 are affected. This includes all stable channel releases released before the update noted in the official Chrome release blog.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating medium severity. An attacker can exploit it by serving a crafted HTML page to a user who opens it in the affected browser. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. Since the exploit requires a page with malicious content, the risk remains medium until the affected versions are removed from use.
OpenCVE Enrichment
Debian DLA
Debian DSA