Junglewise Threat Intelligence

CVE-2026-13023: Google Chrome uninitialized use in GPU

CVE-2026-13023 · Severity: info · Published 2026-06-24

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics processing component could allow a remote attacker to access sensitive information from the computer's memory. This typically requires the attacker to first compromise a separate part of the browser and then trick a user into visiting a malicious website.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the GPU component of Google Chrome. The flaw allows a remote attacker to obtain sensitive information from process memory. To exploit this, an attacker must have already compromised the renderer process and then entice a user to visit a specially crafted HTML page. The vulnerability was reported by Google internal researchers and is addressed in Chrome version 149.0.7827.197 and later.

Affected products

  • Google Chrome prior to 149.0.7827.197

Timeline

  • 2026-05-27: disclosed: Reported to Chromium project
  • 2026-06-23: patched: Stable channel update released
  • 2026-06-24: advisory: NVD publication date

References

Related threats