Executive brief
A vulnerability in Google Chrome's graphics engine could allow a malicious website to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of private data from other open tabs or browser processes. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
This vulnerability is classified as an uninitialized use (CWE-457) within Skia, the open-source 2D graphics library used by Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading the engine to read from memory locations that have not been properly initialized. A remote, unauthenticated attacker can exploit this to leak sensitive data from the Chrome process memory. The attack requires minimal user interaction, typically just visiting a malicious website. Google has addressed this issue in Chrome version 150.0.7871.125.
Affected products
- Google Chrome < 150.0.7871.125
Timeline
- 2026-05-17: other: Reported by Google internal researchers
- 2026-07-14: disclosed
- 2026-07-14: patched: Fixed in version 150.0.7871.125