Junglewise Threat Intelligence

CVE-2026-14408: Google Chrome uninitialized use in Dawn

CVE-2026-14408 · Severity: info · CVSS 6.5 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Dawn component, which handles graphics processing. A remote attacker could use a specially crafted website to trick the browser into revealing sensitive information from its memory. This could potentially expose private data from other open tabs or browser processes to the attacker.

Technical details

An uninitialized use vulnerability (CWE-457) exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory during graphics rendering operations. A remote, unauthenticated attacker can exploit this to perform a side-channel attack or direct memory leak, potentially obtaining sensitive information from the browser's process memory. The vulnerability is resolved in Google Chrome version 150.0.7871.46 and later.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Stable channel update released for desktop
  • 2026-07-01: disclosed: CVE published to NVD

References

Related threats