Junglewise Threat Intelligence

CVE-2026-11067: Google Chrome uninitialized use in Dawn

CVE-2026-11067 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Dawn graphics component could allow a malicious website to access sensitive information from the browser's memory. This could potentially lead to the exposure of private user data or technical details that help an attacker bypass other security protections.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the Dawn component of Google Chrome. Dawn is the implementation of the WebGPU standard in Chromium. By enticing a user to visit a specially crafted HTML page, a remote attacker can trigger the use of uninitialized variables, leading to an information disclosure of sensitive data from the browser's process memory. The vulnerability is fixed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats