Junglewise Threat Intelligence

CVE-2026-17771: Google Chrome uninitialized use in Skia

CVE-2026-17771 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's Skia graphics engine, which is responsible for rendering 2D graphics and text. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to access sensitive data from other websites the user has open. This could lead to the exposure of private information, such as login tokens or personal data, across different browser tabs.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists within the Skia graphics library component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory during rendering operations. A remote, unauthenticated attacker can leverage this to bypass cross-origin resource sharing (CORS) protections and leak sensitive data from different origins. The issue was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats