Junglewise Threat Intelligence

CVE-2026-13030: Google Chrome uninitialized use in GPU

CVE-2026-13030 · Severity: info · Published 2026-06-24

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A security flaw in the browser's graphics processing component could allow a malicious website to access sensitive information stored in the device's memory. This could lead to the exposure of private data from other open tabs or browser processes.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the GPU component of Google Chrome for Android. The flaw occurs when the browser attempts to use a variable or memory region that has not been properly initialized, potentially leaking the contents of previously stored data. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to read sensitive information from the browser's process memory. The issue is resolved in version 149.0.7827.197 and later.

Affected products

  • Google Chrome < 149.0.7827.197

Timeline

  • 2026-06-11: other: Reported to Chromium project
  • 2026-06-23: patched: Stable channel update released
  • 2026-06-24: disclosed: NVD publication date

References

Related threats