Executive brief
A vulnerability in Google Chrome's graphics engine could allow an attacker to access sensitive information from the browser's memory. This occurs if a user visits a specially crafted website and the attacker has already partially compromised the browser's internal rendering process. Such an exploit could lead to the exposure of private data or credentials stored in memory.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the Skia component of Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process (a sandbox-escape or multi-stage attack scenario). By exploiting this uninitialized variable, a remote attacker can read potentially sensitive information from the process memory. The issue was addressed in Google Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched