Junglewise Threat Intelligence

CVE-2026-14421: Google ChromeOS uninitialized use in Dawn

CVE-2026-14421 · Severity: info · CVSS 4.3 · Published 2026-07-01

Technologies: Google ChromeOS. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome on ChromeOS that could allow a malicious website to access sensitive information from the browser's memory. This occurs when the browser's graphics component fails to properly initialize data before using it. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the exposure of private user data.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the Dawn component of Google Chrome on ChromeOS. Dawn is the underlying implementation of the WebGPU standard. The flaw allows a remote attacker to bypass memory safety protections by serving a specially crafted HTML page that triggers the use of uninitialized variables within the Dawn process. Successful exploitation enables the attacker to read potentially sensitive information from the browser's process memory. The issue is addressed in ChromeOS version 150.0.7871.46.

Affected products

  • Google ChromeOS prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fix released in Chrome 150.0.7871.46 stable channel update.
  • 2026-07-01: disclosed: NVD publication date.

References

Related threats