Executive brief
A vulnerability in Google Chrome for Mac could allow a remote attacker to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted website, potentially exposing data from other open tabs or browser processes. The issue has been resolved in the latest software update.
Technical details
A vulnerability classified as CWE-457 (Use of Uninitialized Variable) exists in the WebML component of Google Chrome for macOS. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory. A remote, unauthenticated attacker can exploit this to perform a memory disclosure attack, potentially recovering sensitive data from the browser's process memory. This issue was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53/54 for Mac
- 2026-06-04: disclosed: CVE published by NVD