AI analysis
Google Chrome prior to version 154.0.8037.92 contains a use of uninitialized memory (CWE-908) in Skia, the browser's core graphics rendering library. A remote attacker triggers the flaw by luring a victim to a crafted HTML page, causing Skia to read uninitialized memory that can hold data belonging to another origin, effectively bypassing the same-origin policy. Successful exploitation yields a limited confidentiality impact — theft of cross-origin data — with no integrity or availability impact; Google rates the bug High severity even though the NVD CVSS base score is only 4.3 (medium). All users running Chrome older than 154.0.8037.92 are affected, and most Chromium-based derivatives that bundle the same Skia code remain exposed until they ship builds incorporating the fix. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.
What to do: Update Google Chrome to version 154.0.8037.92 or later, then relaunch the browser — updates only apply on restart, so check Settings > About Chrome (chrome://settings/help) for a pending update. Enterprise and education admins should verify fleet-wide browser versions and force updates via policy, since every pre-154 device is one crafted link away from cross-origin data theft. Users of Chromium-based browsers such as Edge, Brave, Opera, and Vivaldi should apply those vendors' latest updates, which pick up the patched Skia code.
Affected
| Google Chrome | < 154.0.8037.92 |
Estimated exposure
mass≈2–3 billion users (Chrome holds roughly two-thirds of global browser market share) — Estimated by applying Chrome's dominant desktop and mobile browser market share (about 65%) to the roughly 4–5 billion people who use the internet, since any pre-154.0.8037.92 install is vulnerable to a single malicious webpage.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.