Executive brief
Google Chrome is a widely used web browser. A vulnerability was identified in its ANGLE graphics engine component on Windows that could allow a malicious website to access sensitive information from the browser's memory. This could potentially lead to the exposure of private data from other open tabs or browser processes if a user visits a specially crafted webpage.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read sensitive information from the process memory. This is a medium-severity information disclosure bug that requires the victim to navigate to a malicious site. The issue was addressed in Chrome version 151.0.7922.72 for Windows.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date