Executive brief
Google Chrome on Android is affected by a security vulnerability in its WebGL component, which is used for rendering 3D graphics in the browser. A remote attacker could use a specially crafted website to access sensitive data from other websites you have open. This could lead to the exposure of private information or session data across different web origins.
Technical details
A vulnerability classified as 'Uninitialized Use' (CWE-457) exists in the WebGL component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass cross-origin restrictions. This can result in the leakage of sensitive data from different origins. The issue was addressed in version 151.0.7922.72. Exploitation requires the victim to navigate to a malicious webpage, but no special privileges are required by the attacker.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date