Junglewise Threat Intelligence

CVE-2026-17714: Google Chrome uninitialized use in ANGLE

CVE-2026-17714 · Severity: info · CVSS 7.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's ANGLE component, which handles graphics processing. By tricking a user into visiting a specially crafted website, a remote attacker could access sensitive information stored in the browser's memory. This could lead to the exposure of private data or help facilitate further attacks against the user's system.

Technical details

A vulnerability classified as 'Uninitialized Use' (CWE-457) exists within the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized variables during graphics rendering. A remote, unauthenticated attacker can exploit this to leak sensitive information from the browser's process memory. This issue was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats