Executive brief
A vulnerability exists in Google Chrome's graphics layer (ANGLE) that could allow a malicious website to access sensitive information from the browser's memory. By tricking a user into visiting a specially crafted webpage, an attacker could potentially read data that should be private, such as fragments of other open tabs or internal browser data. This issue has been resolved in the latest version of Chrome.
Technical details
A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists within the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory during graphics rendering operations. A remote, unauthenticated attacker can exploit this to read sensitive information from the Chrome process memory. The vulnerability is addressed in Google Chrome version 149.0.7827.53 and later. Exploitation requires user interaction (visiting a malicious site).
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
- 2026-06-04: disclosed: NVD publication date