Junglewise Threat Intelligence

CVE-2026-14402: Google Chrome uninitialized use in ANGLE

CVE-2026-14402 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability was identified in its ANGLE graphics engine that could allow a malicious website to access sensitive information from the browser's memory. This could potentially lead to the exposure of private data while a user is browsing the web.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read sensitive information from the process memory. This is a result of the engine using a variable before it has been properly initialized. The vulnerability was addressed in Chrome version 150.0.7871.46. Exploitation requires the victim to visit a malicious network location but does not require prior authentication.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 151 stable channel update released containing fixes for version 150.
  • 2026-07-01: advisory: NVD publication date.

References

Related threats