Executive brief
A vulnerability in Google Chrome for Mac could allow a remote attacker to access sensitive information from other websites. By tricking a user into visiting a specially crafted webpage, an attacker can exploit a flaw in the browser's graphics engine to leak data across security boundaries. This could lead to the exposure of private user information or session data.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the ANGLE graphics engine component of Google Chrome on macOS. The flaw is triggered when the browser processes a specially crafted HTML page, leading to a condition where uninitialized memory is utilized during graphics rendering. A remote, unauthenticated attacker can exploit this to bypass cross-origin restrictions and leak sensitive data from other browser contexts. The vulnerability is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-17: disclosed: Reported to Chromium by Google researchers
- 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47 for Mac
- 2026-06-30: advisory