Junglewise Threat Intelligence

CVE-2026-17757: Google Chrome uninitialized use in Skia graphics engine

CVE-2026-17757 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's graphics engine that could allow a malicious website to access data from other websites you have open. This occurs because the browser fails to properly clear memory before using it, potentially exposing sensitive information across different browser tabs. Users should update to the latest version of Chrome to protect their private data.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists within the Skia graphics library used by Google Chrome. The flaw is triggered when the engine processes a specially crafted HTML page, leading to the use of uninitialized memory during rendering operations. A remote, unauthenticated attacker can exploit this to bypass Same-Origin Policy (SOP) protections and leak sensitive cross-origin data. The issue is resolved in Chrome version 151.0.7922.72 and later.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats