Executive brief
A vulnerability exists in Google Chrome's ANGLE component, which is responsible for processing graphics. A remote attacker could use a specially crafted website to bypass security boundaries and access sensitive data from other open websites or browser sessions. This could lead to the unauthorized exposure of private user information or login session data.
Technical details
This vulnerability is classified as a Use of Uninitialized Variable (CWE-457) within ANGLE, the graphics abstraction layer used by Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to a state where uninitialized memory is utilized. An attacker can exploit this to bypass Same-Origin Policy (SOP) protections and leak sensitive cross-origin data. The vulnerability was addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-14: disclosed: Reported by Google internal researchers
- 2026-07-29: patched: Fixed in Chrome Stable Channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date