Junglewise Threat Intelligence

CVE-2026-15766: Google Chrome uninitialized use in Skia

CVE-2026-15766 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a malicious website to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of private data from other open tabs or browser processes. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

This vulnerability is classified as an uninitialized use (CWE-457) within Skia, the open-source 2D graphics library used by Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading the engine to read from memory locations that have not been properly initialized. A remote, unauthenticated attacker can exploit this to leak sensitive data from the Chrome process memory. The attack requires minimal user interaction, typically just visiting a malicious website. Google has addressed this issue in Chrome version 150.0.7871.125.

Affected products

  • Google Chrome < 150.0.7871.125

Timeline

  • 2026-05-17: other: Reported by Google internal researchers
  • 2026-07-14: disclosed
  • 2026-07-14: patched: Fixed in version 150.0.7871.125

References

Related threats