Executive brief
A vulnerability in Google Chrome for Android could allow a remote attacker to access sensitive information from the device's memory. This occurs when a user visits a specially crafted, malicious website. An exploit could lead to the exposure of private data handled by the browser's graphics processing component.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the GPU component of Google Chrome on Android. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory variables during graphics rendering. A remote, unauthenticated attacker can exploit this to read sensitive information from the browser's process memory. This vulnerability was addressed in Chrome version 148.0.7778.216.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop and Android fixes.
- 2026-05-28: disclosed: CVE published to the NVD.