Executive brief
A vulnerability in Google Chrome's WebNN component on Windows could allow a malicious website to access data from other websites. This occurs when the browser uses uninitialized memory, potentially leaking sensitive information across security boundaries. Users are protected by updating to the latest version of the Chrome browser.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the Web Neural Network (WebNN) API implementation in Google Chrome for Windows. The flaw is triggered when the browser fails to properly initialize memory before use, which can be exploited by a remote attacker who entices a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform a side-channel attack to leak cross-origin data, bypassing Same-Origin Policy (SOP) protections. This issue was addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: disclosed
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: advisory