Executive brief
A security vulnerability has been identified in Google Chrome for Windows that could allow a remote attacker to access sensitive information. By tricking a user into visiting a specially crafted website, an attacker could read data from the browser's memory that they should not have access to. This could potentially expose private user data or internal browser information, compromising user privacy and security.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the Codecs component of Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory during media decoding. A remote, unauthenticated attacker can exploit this to read sensitive information from the browser's process memory. This vulnerability was addressed in Google Chrome version 150.0.7871.47 for Windows.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched