AI analysis
An uninitialized resource in Chrome's GPU stack (CWE-908) on Android, fixed in version 154.0.8037.92, allowed a remote attacker to read cross-origin data by luring a victim to a crafted HTML page. The bug causes the browser to expose uninitialized GPU memory, breaking the same-origin policy and leaking data from other origins the browser has processed. Only Chrome on Android is named as affected, and exploitation requires user interaction (visiting a malicious page), which is why the NVD score is a moderate 4.3 despite Google's internal High rating. The fix shipped as part of Chrome 154, an update that patched 32 flaws including a critical ANGLE (GPU translation layer) bug. There is no public proof of concept, no confirmed exploitation in the wild, and the CVE is not on CISA's KEV list.
What to do: Update Chrome on Android to 154.0.8037.92 or later immediately via Google Play or Settings > About Chrome, and confirm the version at chrome://settings/help. Mobile device administrators should verify fleet-wide patch levels, since Android browser auto-updates can lag by days. Because exploitation requires visiting a crafted page, users on unpatched builds should avoid following links from untrusted sources.
Affected
| Google Chrome (Android) | < 154.0.8037.92 |
Estimated exposure
masspotentially 1B+ users (Chrome on Android is preinstalled/dominant on Android devices worldwide) — Chrome for Android has on the order of billions of active installations globally due to being the default browser on Android, so the pool of unpatched devices at any given time is likely in the tens to hundreds of millions until…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.