Junglewise Threat Intelligence

CVE-2026-13943: Google Chrome for Android uninitialized use in CSS

CVE-2026-13943 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in how the browser handles website styling (CSS) could allow a malicious website to peek into the device's memory. This could result in the exposure of sensitive information from other open tabs or browser processes to an attacker.

Technical details

A vulnerability classified as 'Uninitialized Use' (CWE-457) exists in the CSS engine of Google Chrome on Android. The flaw is triggered when the browser processes a specially crafted HTML page containing malicious CSS, leading to the use of uninitialized memory variables. A remote, unauthenticated attacker can exploit this to read sensitive data from the browser's process memory. This issue was addressed in version 150.0.7871.47. The vulnerability is rated as Medium severity by Chromium.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats