Executive brief
Google Chrome contains a security vulnerability in its ANGLE graphics component, which is responsible for translating graphics commands. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could bypass security boundaries to access sensitive data from other websites the user has open, potentially leading to the theft of login sessions or personal information.
Technical details
A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw occurs when the engine attempts to use a variable that has not been properly initialized, leading to predictable or leaked memory contents. A remote attacker can exploit this by hosting a malicious HTML page that, when rendered by a vulnerable browser, triggers the uninitialized use to leak cross-origin data. This bypasses the Same-Origin Policy (SOP), allowing the attacker to read data from other domains. The issue is resolved in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-14: disclosed: Reported to Chromium project
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date