Impact
The CVSS score is 3.4, however the Chromium security team has classified this vulnerability as High, indicating significant risk. The flaw originates from an uninitialized GPU resource in Google Chrome. A remote attacker who has already compromised the renderer process can use a crafted webpage to trigger Chrome to read memory outside the sandbox, leaking data from other processes.
Affected Systems
Affected devices run any version of Google Chrome prior to 153.0.8010.36 on the desktop stable channel. The flaw does not affect Chrome versions 153.0.8010.36 and newer, which contain the applied fix.
Risk and Exploitability
The Chromium security severity assessment assigns this vulnerability a High rating, highlighting the potential for serious information disclosure. The EPSS score of < 1% indicates a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. The required privilege level is the compromised renderer process, and the attacker must supply a malicious webpage. When those conditions are met, the attacker can read arbitrary memory, enabling further compromise such as credential theft or data exfiltration.
OpenCVE Enrichment
Debian DLA
Debian DSA