Executive brief
Google Chrome is a widely used web browser. A security vulnerability was identified in its ANGLE component, which handles graphics processing. If a user visits a specially crafted malicious website, an attacker could exploit this flaw to access sensitive data from other websites the user has open, potentially leading to the exposure of private information or login sessions.
Technical details
A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory during graphics rendering operations. A remote, unauthenticated attacker can leverage this to bypass Same-Origin Policy (SOP) protections and leak sensitive cross-origin data. The issue was addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-27: disclosed: Reported to Chromium project
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date