Junglewise Threat Intelligence

CVE-2026-14399: Google Chrome uninitialized use in Dawn

CVE-2026-14399 · Severity: info · CVSS 6.5 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in its Dawn graphics component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to read sensitive information from the computer's memory. This could lead to the exposure of private data or credentials used within the browser session.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists in the Dawn component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of memory that has not been properly initialized. A remote, unauthenticated attacker can exploit this to leak sensitive information from the browser's process memory. The issue was addressed in Google Chrome version 150.0.7871.46. The attack requires minimal user interaction (visiting a malicious site) and is reachable over the network.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fix released in Chrome 150.0.7871.46 stable channel update.
  • 2026-07-01: advisory: NVD published the CVE record.

References

Related threats