Executive brief
A vulnerability in the Google Chrome web browser could allow a remote attacker to access sensitive information from the computer's memory. This occurs when the browser processes specially crafted media content on a website. An attacker could exploit this by tricking a user into visiting a malicious webpage, potentially leading to the exposure of private data from other open tabs or browser processes.
Technical details
An uninitialized use vulnerability (CWE-457) exists within the Codecs component of Google Chrome for Windows. The flaw is triggered when the browser processes media content via a specially crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to an information disclosure where sensitive data is read from uninitialized process memory. This vulnerability was addressed in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47