Executive brief
Google Chrome is a widely used web browser. A vulnerability in its Dawn graphics component could allow a malicious website to access sensitive information from the browser's memory. This could potentially lead to the exposure of private user data or technical details that help an attacker bypass other security protections.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the Dawn component of Google Chrome. Dawn is the implementation of the WebGPU standard in Chromium. By enticing a user to visit a specially crafted HTML page, a remote attacker can trigger the use of uninitialized variables, leading to an information disclosure of sensitive data from the browser's process memory. The vulnerability is fixed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: NVD publication date