Junglewise Threat Intelligence

CVE-2026-12469: Google Chrome uninitialized use in GPU

CVE-2026-12469 · Severity: medium · CVSS 4.3 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to access data from other websites you have open. This occurs due to a technical error in how the browser handles graphics processing. An attacker would need to trick a user into visiting a specially crafted webpage to trigger the leak.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the GPU component of Google Chrome for Android. The flaw allows a remote attacker to bypass cross-origin isolation by enticing a user to visit a malicious HTML page. By exploiting the uninitialized state in the graphics processing unit's memory handling, the attacker can read sensitive data belonging to other origins. The issue is resolved in version 149.0.7827.155 and later.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-06-09: disclosed: Reported to Chromium by Google researchers
  • 2026-06-16: patched: Stable channel update released for desktop and Android versions
  • 2026-06-17: advisory: NVD publication date

References

Related threats