Impact
Google Chrome for Android contains an uninitialized memory use in the WebGL subsystem that allows a remote attacker to leak data across origins. The flaw is exploitable through a specially crafted HTML page that a victim may load, resulting in the attacker gaining access to information that should remain confined to the origin of the page. The weakness is classified as CWE-457 and CWE-824.
Affected Systems
The vulnerability is present in Google Chrome on Android versions prior to 148.0.7778.216. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 7.4 reflects a high severity rating by Chromium. The EPSS score is 0.00032, indicating a very low but non‑zero probability of exploitation. The lack of a KEV listing and the high severity suggest that the vulnerability remains a priority for users running an outdated browser. The likely attack vector is a remote attacker delivering a malicious page to a user, prompting them to visit or view the page. The flaw can be triggered without any additional user interaction beyond opening the crafted content, and the attack can happen without elevated privileges on the device.
OpenCVE Enrichment