Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A security vulnerability in its graphics rendering component (WebGL) could allow a malicious website to steal information from other websites you have open. This could lead to the exposure of sensitive user data or browsing history if a user visits a specially crafted web page.
Technical details
A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists in the WebGL component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an uninitialized memory state. A remote attacker can exploit this condition to bypass cross-origin isolation and leak sensitive information from different origins. The vulnerability was addressed in version 148.0.7778.216. The attack requires no special privileges other than enticing a user to visit a malicious URL.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop and mobile versions.
- 2026-05-28: disclosed: CVE published to NVD.