Junglewise Threat Intelligence

CVE-2026-10977: Google Chrome uninitialized use in Skia

CVE-2026-10977 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Skia graphics engine could allow a remote attacker who has already partially compromised the browser's rendering process to steal sensitive data from other websites. This could lead to the exposure of private user information or login credentials across different web domains.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the Skia graphics library component of Google Chrome. The flaw is reachable by a remote attacker who has already achieved code execution within a compromised renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit this uninitialized state to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. This vulnerability was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats