Impact
An out-of-bounds read was discovered in the WebGL implementation of Google Chrome on Android devices. The flaw allows a remote attacker, using a crafted HTML page, to read memory addresses outside the sandboxed process space. This leakage can expose proprietary data, secrets, or kernel memory, resulting in information disclosure and potentially facilitating further attacks.
Affected Systems
The issue affects Google Chrome on Android versions earlier than 153.0.8010.47. It is inferred that all Android devices employing the WebGL graphics stack are potentially impacted, though the description does not explicitly state device coverage. The vulnerability does not affect other browser components.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity. EPSS is below 1%, implying a rare exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented active exploitation. Attackers would need to lure a user to a malicious web page that activates WebGL. The described exploit requires only a crafted page; no additional payload is necessary. Despite the low EPSS, the Critical Chromium severity underscores the importance of addressing the bug promptly.
OpenCVE Enrichment