Impact
Google Chrome on Android before version 153.0.8010.36 uses an uninitialized GPU resource that can be accessed by a renderer process that has already been compromised. A malicious site can craft an HTML page that causes the renderer to read memory outside the sandbox, exposing sensitive data such as cookies or credential information. This flaw is a memory disclosure vulnerability and allows attackers to bypass process isolation that is intended to protect user data.
Affected Systems
The affected product is Google Chrome for Android, specifically any installation older than version 153.0.8010.36. All Android devices running these older Chrome builds are vulnerable; other browsers or vendors are not listed.
Risk and Exploitability
The CVSS score of 3.4 and an EPSS score of less than 1% indicate a moderate severity with a very low but non‑zero likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. Exploitation requires the renderer process to be already compromised and a crafted web page to be delivered, limiting the attack surface to remote web content. Although the risk of exploitation is low, memory disclosure still poses a potential impact to user confidentiality.
OpenCVE Enrichment
Debian DLA
Debian DSA