Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics translation engine (ANGLE) could allow a malicious website to access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information across different web sessions.
Technical details
A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an uninitialized memory state. A remote, unauthenticated attacker can exploit this to bypass cross-origin isolation and leak sensitive data from other origins. The issue is addressed in Chrome version 149.0.7827.53 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published to NVD