Junglewise Threat Intelligence

CVE-2026-13950: Google Chrome uninitialized use in GPU

CVE-2026-13950 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics processing component could allow a remote attacker to access sensitive information from the computer's memory. This could potentially expose private data if a user visits a specially crafted malicious website.

Technical details

This vulnerability is classified as a Use of Uninitialized Variable (CWE-457) within the GPU component of Google Chrome. The flaw allows a remote attacker to leak sensitive information from the process memory. To exploit this, an attacker must first compromise the renderer process and then entice a user to visit a malicious HTML page. The vulnerability was addressed in Chrome version 150.0.7871.47. Google tracks this internally as issue 513360781 and assigned a Chromium security severity of Medium.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats