Junglewise Threat Intelligence

CVE-2026-11101: Google Chrome uninitialized use in Dawn

CVE-2026-11101 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Dawn component could allow a malicious website to access data from other websites you have open. This occurs because the browser fails to properly clear memory before use, potentially exposing sensitive information across different web origins. Users are protected by updating to the latest version of the Chrome browser.

Technical details

An uninitialized use vulnerability (CWE-457) exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of memory that has not been properly initialized. A remote, unauthenticated attacker can exploit this to bypass cross-origin isolation and leak sensitive data from other origins. This issue specifically affected Chrome on Windows prior to version 149.0.7827.53. Google has released a patch to address this behavior by ensuring proper memory initialization.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published by NVD/Chrome

References

Related threats