Junglewise Threat Intelligence

CVE-2026-9921: Google Chrome WebGL uninitialized use information disclosure

CVE-2026-9921 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A security vulnerability in its graphics rendering component (WebGL) could allow a malicious website to steal information from other websites you have open. This could lead to the exposure of sensitive user data or browsing history if a user visits a specially crafted web page.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists in the WebGL component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an uninitialized memory state. A remote attacker can exploit this condition to bypass cross-origin isolation and leak sensitive information from different origins. The vulnerability was addressed in version 148.0.7778.216. The attack requires no special privileges other than enticing a user to visit a malicious URL.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop and mobile versions.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats