Executive brief
A vulnerability in Google Chrome's graphics layer could allow a malicious website to access information from other open websites. This occurs when the browser uses uninitialized memory during graphics processing, potentially leading to the exposure of sensitive user data across different origins. Users are advised to update their browser to the latest version to mitigate this risk.
Technical details
A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows. The flaw allows a remote attacker to bypass cross-origin isolation by enticing a user to visit a specially crafted HTML page. By exploiting the uninitialized memory state during graphics rendering, the attacker can potentially read data belonging to other origins. This issue was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-05: disclosed: CVE published in NVD.