Junglewise Threat Intelligence

CVE-2026-17740: Google Chrome uninitialized use in ANGLE

CVE-2026-17740 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics processing component could allow a malicious website to access data from other websites you have open. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of sensitive information across different browser tabs. Google has released an update to address this issue.

Technical details

A vulnerability classified as 'Uninitialized Use' (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation and leak sensitive data from other origins. The issue is resolved in Google Chrome version 151.0.7922.72 and later.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: advisory

References

Related threats