Junglewise Threat Intelligence

CVE-2026-10976: Google Chrome uninitialized use in Dawn

CVE-2026-10976 · Severity: info · CVSS 7.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Dawn component could allow a remote attacker to access sensitive information from the browser's memory. By tricking a user into visiting a specially crafted website, an attacker could potentially read data belonging to other tabs or the browser process itself. This could lead to the exposure of private user data or session information.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the Dawn component of Google Chrome. Dawn is the implementation of the WebGPU standard in Chromium. The flaw allows a remote attacker to trigger the use of uninitialized variables by enticing a user to visit a malicious website containing a crafted HTML page. Successful exploitation enables the attacker to leak sensitive information from the browser's process memory. The vulnerability is addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update.
  • 2026-06-04: disclosed: NVD publication date.

References

Related threats