Executive brief
A vulnerability exists in Google Chrome's Dawn component, which is responsible for handling modern web graphics. An attacker who has already partially compromised the browser's content-rendering process could exploit this flaw to read sensitive information from the computer's memory. This could lead to the exposure of private data or help an attacker bypass other security protections.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the Dawn component of Google Chrome. The flaw is reachable via a crafted HTML page, though it requires the attacker to have already achieved a compromise of the renderer process (a 'sandbox escape' or similar initial foothold is not provided by this bug alone). By exploiting this uninitialized variable, a remote attacker can perform an out-of-bounds read or otherwise leak sensitive information from the process memory. This issue is resolved in Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date