Junglewise Threat Intelligence

CVE-2026-13923: Google Chrome uninitialized use in GPU on Android

CVE-2026-13923 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a popular web browser used on mobile devices. A security vulnerability in the browser's graphics processing component could allow a malicious website to read small amounts of sensitive information from the device's memory. This could potentially expose private data to an attacker if a user visits a specially crafted web page.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists within the GPU component of Google Chrome on Android. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an uninitialized memory read. A remote, unauthenticated attacker can exploit this to leak sensitive information from the browser's process memory. The issue was addressed in version 150.0.7871.47. The vulnerability requires user interaction (visiting a malicious site) but can be executed over the network.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats