Executive brief
Google Chrome is a widely used web browser. A vulnerability was identified in its ANGLE graphics engine that could allow a malicious website to access sensitive information from the browser's memory. This could potentially lead to the exposure of private data while a user is browsing the web.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read sensitive information from the process memory. This is a result of the engine using a variable before it has been properly initialized. The vulnerability was addressed in Chrome version 150.0.7871.46. Exploitation requires the victim to visit a malicious network location but does not require prior authentication.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 151 stable channel update released containing fixes for version 150.
- 2026-07-01: advisory: NVD publication date.