Junglewise Threat Intelligence

CVE-2026-9917: Google Chrome uninitialized use in WebGL

CVE-2026-9917 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics rendering component (WebGL) could allow a malicious website to access sensitive information from the browser's memory. This could potentially expose private data or help an attacker bypass security protections while a user is browsing the web on an Android device.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the WebGL component of Google Chrome on Android. By convincing a user to visit a specially crafted HTML page, a remote attacker can trigger the use of uninitialized variables during graphics rendering. This flaw allows the attacker to read potentially sensitive information from the browser's process memory. The vulnerability is fixed in version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop and Android.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats