Executive brief
Google Chrome is a widely used web browser. A security vulnerability was identified in its V8 engine, which is responsible for processing JavaScript. If a user visits a specially crafted malicious website, an attacker could potentially read sensitive information from the computer's memory, which might include data from other open tabs or private browsing sessions.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine attempts to use a variable or memory region that has not been properly initialized. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation allows the attacker to perform an out-of-bounds read of process memory, potentially leaking sensitive information. The issue is resolved in Chrome version 150.0.7871.125.
Affected products
- Google Chrome prior to 150.0.7871.125
Timeline
- 2026-06-17: disclosed: Reported by Google internal researchers
- 2026-07-14: patched: Fixed in stable channel update 150.0.7871.125
- 2026-07-14: advisory