Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its graphics processing component could allow a remote attacker to access sensitive information from the computer's memory. This typically requires the attacker to first compromise a separate part of the browser and then trick a user into visiting a malicious website.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the GPU component of Google Chrome. The flaw allows a remote attacker to obtain sensitive information from process memory. To exploit this, an attacker must have already compromised the renderer process and then entice a user to visit a specially crafted HTML page. The vulnerability was reported by Google internal researchers and is addressed in Chrome version 149.0.7827.197 and later.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-05-27: disclosed: Reported to Chromium project
- 2026-06-23: patched: Stable channel update released
- 2026-06-24: advisory: NVD publication date