Junglewise Threat Intelligence

CVE-2026-13970: Google Chrome uninitialized use in Media

CVE-2026-13970 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser for accessing the internet. A vulnerability in the browser's media component could allow an attacker who has already partially compromised the browser to steal sensitive information from the computer's memory. This could lead to the exposure of private data such as passwords or browsing history if a user visits a malicious website.

Technical details

This vulnerability (CWE-457) involves the use of uninitialized memory within the Media component of Google Chrome. The flaw is reachable by a remote attacker who has already achieved code execution within the sandboxed renderer process (e.g., via a separate exploit). By enticing a user to visit a specially crafted HTML page, the attacker can leverage this uninitialized state to leak sensitive information from the process memory. This issue was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats