MEDIUM
CVE-2026-13030
CVSS
5.3
Description
Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
An uninitialized use vulnerability in the GPU component of Google Chrome on Android allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability exists in versions prior to 149.0.7827.197.
Mitigation
Update Google Chrome on Android to version 149.0.7827.197 or later to patch the uninitialized memory read vulnerability in the GPU renderer.
Weakness (CWE)
CWE-457
EPSS Score
0.29%
Probability of exploitation in next 30 days
21.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.