Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in the browser's graphics processing component could allow a malicious website to access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information across different web sessions.
Technical details
A vulnerability classified as 'Uninitialized Use' (CWE-457) exists within the GPU component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory. A remote attacker can exploit this to bypass cross-origin isolation and leak sensitive data from other origins. The issue is addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed