MEDIUM

CVE-2026-13023

Google Chrome 2026-06-24 CVSS v3.1
CVSS
5.3

Description

Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

This is an uninitialized memory use vulnerability in Google Chrome's GPU process. A remote attacker who has already compromised the renderer process can exploit this to read potentially sensitive information from process memory via a specially crafted HTML page. The vulnerability stems from improper initialization of data structures in the GPU component before they are accessed.

Mitigation

Update Google Chrome to version 149.0.7827.197 or later. Organizations should apply the patch through their standard patch management process and verify complete deployment.

Weakness (CWE)

CWE-457

EPSS Score

0.29%
Probability of exploitation in next 30 days
21.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE