Junglewise Threat Intelligence

CVE-2026-17949: Google Chrome for Android uninitialized use in GPU

CVE-2026-17949 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in the browser's graphics processing component could allow a malicious website to access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information across different web sessions.

Technical details

A vulnerability classified as 'Uninitialized Use' (CWE-457) exists within the GPU component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory. A remote attacker can exploit this to bypass cross-origin isolation and leak sensitive data from other origins. The issue is addressed in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats