Junglewise Threat Intelligence

CVE-2026-17785: Google Chrome uninitialized use in ANGLE

CVE-2026-17785 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's graphics engine (ANGLE) that could allow a malicious website to access data from other websites you have open. This occurs when the browser fails to properly clear memory before using it, potentially exposing sensitive information across different web origins. To protect yourself, ensure your browser is updated to the latest version.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists within the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the engine utilizes memory that has not been properly initialized, which can be exploited by a remote attacker who entices a user to visit a malicious HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation and leak sensitive data from other origins. The issue is resolved in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats