Junglewise Threat Intelligence

CVE-2026-10994: Google Chrome uninitialized use in ANGLE

CVE-2026-10994 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's graphics engine (ANGLE) that could allow a malicious website to access sensitive information. By tricking a user into visiting a specially crafted webpage, an attacker could potentially read data from the browser's memory. This could lead to the exposure of private information handled by the browser process.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists within the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw occurs when the engine attempts to use memory that has not been properly initialized, which can be triggered by a remote attacker through a specifically crafted HTML page. Successful exploitation allows the attacker to perform an information disclosure attack, reading potentially sensitive data from the browser's process memory. The issue is resolved in Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published and NVD record created

References

Related threats