Impact
An uninitialized GPU resource in Google Chrome for Android before version 153.0.8010.36 permits a remote attacker to read memory outside the sandbox by loading a specially crafted HTML page. The attacker can expose the contents of the device’s memory, potentially revealing sensitive information such as passwords, cryptographic keys, or personal data. This flaw is an example of a memory disclosure vulnerability and is listed under CWE-908.
Affected Systems
Google Chrome running on Android devices that have a version earlier than 153.0.8010.36. Devices using the stable channel prior to the September 2026 update remain vulnerable. No specific manufacturer or operating system level is mentioned beyond the Android platform.
Risk and Exploitability
The vulnerability can be leveraged remotely by any entity that can serve a malicious web page to the target device. The exploit has a CVSS score of 4.7, indicating medium severity, an EPSS score of <1%, and it is not listed in the CISA KEV catalog. Given the lack of a known exploit in the wild, the risk remains moderate, but the flaw provides a direct path to read confidential data from the sandboxed environment.
OpenCVE Enrichment
Debian DLA
Debian DSA