Junglewise Threat Intelligence

CVE-2026-13969: Google Chrome for Android uninitialized use in UI

CVE-2026-13969 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Android that could allow a malicious website to access sensitive information. If a user visits a specially crafted webpage, an attacker who has already partially compromised the browser's internal processes could read data from the device's memory. This could lead to the exposure of private user information or browsing data.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the UI component of Google Chrome for Android prior to version 150.0.7871.47. The flaw is exploitable by a remote attacker who has already achieved a compromise of the renderer process. By enticing a user to visit a crafted HTML page, the attacker can leverage this uninitialized state to leak sensitive information from the browser's process memory. This issue was addressed in the stable channel update to version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD publication date
  • 2026-06-30: patched: Stable channel update released

References

Related threats