Executive brief
Google Chrome for Android is a popular web browser used on mobile devices. A security vulnerability in the browser's graphics processing component could allow a malicious website to read small amounts of sensitive information from the device's memory. This could potentially expose private data to an attacker if a user visits a specially crafted web page.
Technical details
A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists within the GPU component of Google Chrome on Android. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an uninitialized memory read. A remote, unauthenticated attacker can exploit this to leak sensitive information from the browser's process memory. The issue was addressed in version 150.0.7871.47. The vulnerability requires user interaction (visiting a malicious site) but can be executed over the network.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory