Executive brief
Google Chrome is a widely used web browser. A vulnerability in its Dawn component, which handles graphics processing, could allow a malicious website to access sensitive information from other websites you have open. This could lead to the theft of personal data or login sessions if a user visits a specially crafted webpage.
Technical details
A vulnerability classified as uninitialized use (CWE-457) exists in Dawn, the WebGPU implementation in Google Chrome. The flaw occurs when the engine attempts to use a variable or memory region that has not been properly initialized. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, potentially leading to a cross-origin information leak. This bypasses the Same-Origin Policy (SOP), allowing the attacker to read data from other domains. The issue is resolved in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.