Impact
The flaw is an uninitialized resource in the WebGL component of Google Chrome that allows a remote attacker to read data from a different origin through a specially crafted HTML page. This behaviour permits the disclosure of sensitive information (such as confidential data or user credentials) that the victim’s browser would normally protect. The weakness is a classic instance of using uninitialized memory, listed as CWE-908, and the severity assigned by Chromium is medium.
Affected Systems
The vulnerability affects Google Chrome versions prior to 153.0.8010.36. All users running older stable releases are susceptible until they install a newer build of Chrome where the WebGL resource is properly initialized.
Risk and Exploitability
The CVSS score is 4.3, and the EPSS score is < 1%, indicating a medium severity with a very low likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog, but the nature of the data leakage could be valuable to an attacker who successfully crafts the malicious page. Because the attack vector requires a browser visit to a malicious web page, it is a remote, user‑initiated exploitation scenario. Once triggered, the attacker can read cross‑origin data available in the victim’s browser session.
OpenCVE Enrichment
Debian DLA
Debian DSA