Junglewise Threat Intelligence

CVE-2026-17759: Google Chrome uninitialized use in Codecs

CVE-2026-17759 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the way the browser handles media codecs could allow a malicious website to access sensitive information stored in the computer's memory. This could potentially lead to the exposure of private data from other open tabs or system processes.

Technical details

This vulnerability is classified as a Use of Uninitialized Variable (CWE-457) within the Codecs component of the Chromium engine. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of memory that has not been properly initialized. A remote, unauthenticated attacker can exploit this to perform a side-channel attack or direct memory read, potentially obtaining sensitive information from the browser's process memory. The issue was addressed in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats