Impact
An uninitialized GPU resource in Google Chrome on Android allows a crafted HTML page to cause the renderer process to read memory outside its sandbox. The read can expose sensitive user data, representing a confidentiality breach. The flaw is classified as CWE‑908.
Affected Systems
Google Chrome for Android versions prior to 154.0.8037.57 are affected. The vulnerability arises in the GPU component handling rendering. Devices running any earlier build need patching to close this path.
Risk and Exploitability
The attacker must form a malicious HTML page and load it in a browser where the renderer is already compromised, implying a local or partially trusted threat. No public exploit code is documented and the EPSS score is unavailable, but the CVE was assigned medium severity. The issue is not yet listed by CISA in its KEV catalog, reducing known exploit prevalence but still posing a substantial risk when the renderer is subverted.
OpenCVE Enrichment
Debian DSA