Junglewise Threat Intelligence

CVE-2026-17992: Google Chrome Skia uninitialized use memory disclosure

CVE-2026-17992 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's graphics engine (Skia) on Windows. A remote attacker could use a specially crafted website to access sensitive information stored in the browser's memory. This could potentially lead to the exposure of private data from other open tabs or browser processes.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the Skia component of Google Chrome on Windows. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of uninitialized memory during graphics rendering. A remote, unauthenticated attacker can exploit this to read sensitive information from the browser's process memory. This issue was addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72 for Windows.
  • 2026-07-30: disclosed: NVD publication date.

References

Related threats