Impact
A flaw in the ANGLE rendering layer of Google Chrome allows an attacker who can serve a specially crafted HTML page to read memory that would normally be inaccessible from within the browser sandbox. The bug occurs when Chrome fails to initialize a resource correctly, leading to uninitialized memory exposure. An attacker who can deliver the page to a user can therefore potentially retrieve sensitive data residing on the host, classifying the vulnerability as a medium risk to confidentiality.
Affected Systems
All installations of Google Chrome before version 153.0.8010.47 are vulnerable. The problem affects consumers and enterprise users who run older stable channel releases of the browser. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, but the description highlights a high‑severity impact. The EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild, and the vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the attack vector is likely via a web page delivered by a compromised or malicious site, which triggers the uninitialized memory read in the sandboxed rendering process.
OpenCVE Enrichment
Debian DLA
Debian DSA