Junglewise Threat Intelligence

CVE-2026-14051: Google Chrome uninitialized use in GamepadAPI

CVE-2026-14051 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Gamepad API could allow an attacker to access sensitive information from the browser's memory. This issue occurs if an attacker has already partially compromised the browser's rendering process and lures a user to a specially crafted website. While the impact is limited to information disclosure, it could be used to facilitate more complex attacks.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the GamepadAPI component of Google Chrome. The flaw allows a remote attacker to read sensitive information from the process memory. Exploitation requires the attacker to have already compromised the renderer process and to entice a user into visiting a malicious HTML page. This vulnerability is categorized as Low severity by Chromium. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats