Junglewise Threat Intelligence

CVE-2026-17810: Google Chrome uninitialized use in Dawn

CVE-2026-17810 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Dawn component could allow a malicious website to access data from other websites you have open. This occurs when the browser fails to properly clear memory before using it, potentially exposing sensitive information across different web origins. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

This vulnerability is classified as a Use of Uninitialized Variable (CWE-457) within Dawn, the WebGPU implementation in Chromium. The flaw allows a remote attacker to potentially access sensitive information across origin boundaries by enticing a user to visit a specially crafted HTML page. The root cause is the failure to initialize memory before it is accessed or returned, which can lead to the disclosure of residual data from other processes or origins. Google has addressed this issue in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats