Impact
An improper implementation of the GPU subsystem in Google Chrome for Android allows a remote attacker to read data from the process memory using a specially crafted HTML page. The flaw permits extraction of potentially sensitive information, such as personal data or credentials, from memory. This information‑exposure weakness is exemplified by CWE‑200 and CWE‑825, which describe unauthorized access to data and improper restriction of operations, respectively. The attack could lead to privacy violations or enable further exploitation of the victim's secrets.
Affected Systems
Google Chrome on Android versions prior to 148.0.7778.216 are affected. Users running any older build of Chrome on Android devices should verify their version and consider upgrading.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. EPSS score indicates a very low exploitation probability (< 1%). The vulnerability is not listed in CISA KEV. The weakness involves CWE‑200 and CWE‑825, revealing an information‑exposure flaw. An attacker can exploit the flaw by delivering a crafted web page to the target, typically through compromised or malicious sites. The attack vector is therefore inferred to be remote via the browser. The potential for data disclosure warrants prompt attention, especially in environments that process sensitive information.
OpenCVE Enrichment
Debian DSA