Junglewise Threat Intelligence

CVE-2026-13825: Google Chrome uninitialized use in Dawn

CVE-2026-13825 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Dawn component, which is responsible for handling modern web graphics. By tricking a user into visiting a specially crafted website, a remote attacker could cause the browser to crash or potentially execute unauthorized code. This could lead to the theft of sensitive information or a full compromise of the user's browsing session.

Technical details

An uninitialized use vulnerability (CWE-457) exists in Dawn, the WebGPU implementation in Google Chrome. The flaw occurs when the application attempts to use a variable or memory region that has not been properly initialized, leading to unpredictable behavior. A remote attacker can exploit this by enticing a user to visit a malicious website containing a crafted HTML page. Successful exploitation can result in heap corruption, which may be leveraged for arbitrary code execution within the context of the browser's renderer process. The vulnerability is fixed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-05-14: disclosed: Reported by Google internally
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats