Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine component (ANGLE) could allow a malicious website to access sensitive information from the browser's memory. This could potentially lead to the exposure of private data or browsing history if a user visits a specially crafted web page.
Technical details
A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory. A remote, unauthenticated attacker can exploit this to leak sensitive information from the browser's process memory. The vulnerability is addressed in Chrome version 150.0.7871.47 and later. Google has categorized the severity of this specific issue as Low.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47