Junglewise Threat Intelligence

CVE-2026-10973: Google Chrome uninitialized use in Dawn

CVE-2026-10973 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Dawn component, which handles graphics processing, could allow a malicious website to access sensitive information from other websites you have open. This could lead to the theft of personal data or login sessions if a user visits a specially crafted webpage.

Technical details

A vulnerability classified as uninitialized use (CWE-457) exists in Dawn, the WebGPU implementation in Google Chrome. The flaw occurs when the engine attempts to use a variable or memory region that has not been properly initialized. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, potentially leading to a cross-origin information leak. This bypasses the Same-Origin Policy (SOP), allowing the attacker to read data from other domains. The issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats