Junglewise Threat Intelligence

CVE-2026-14088: Google Chrome for Android uninitialized use in Canvas

CVE-2026-14088 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A security vulnerability in the browser's Canvas component could allow a malicious website to read sensitive information from the device's memory. This could potentially lead to the exposure of private data from other open tabs or browser processes.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the Canvas component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass memory initialization and read data from the process memory. This is a side-channel information leakage vulnerability that could expose sensitive data residing in the browser's memory space. The issue was addressed in version 150.0.7871.47. No user interaction beyond visiting a malicious site is required for exploitation.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats