Description
Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Uninitialized use in the Dawn rendering engine of Google Chrome creates a potential heap corruption flaw. A crafted HTML page can trigger the bug, which allows a remote attacker to corrupt memory while the page is processed. This memory corruption could lead to arbitrary code execution or a denial‑of‑service condition within the browser context.

Affected Systems

All releases of Google Chrome prior to version 150.0.7871.47 are vulnerable. Versions 150.0.7871.47 and later contain the fix.

Risk and Exploitability

The CVSS score of 8.8 signals high severity. The EPSS score is below 1 %, indicating a low likelihood of exploitation in the wild. This vulnerability is not listed in CISA’s KEV catalog. The advisory describes exploitation via a malicious web page, implying that the attack can be performed remotely without requiring local privileges. However, the lack of explicit privilege requirements is inferred from the described attack scenario and not explicitly stated in the official disclosure.

Generated by OpenCVE AI on July 21, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or newer.
  • Keep Chrome’s automatic update feature enabled to receive security patches promptly.
  • Deploy an enterprise policy that enforces installation of the patched version and blocks older Chrome builds until the update is applied.

Generated by OpenCVE AI on July 21, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chromium Dawn Rendering Engine Causes Potential Heap Corruption

Thu, 16 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chromium Dawn Rendering Engine Causes Potential Heap Corruption

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Engine Causing Heap Corruption

Mon, 13 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Engine Causing Heap Corruption

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Uninitialized Use in Dawn

Fri, 10 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Uninitialized Use in Dawn

Thu, 09 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Rendering Engine May Enable Remote Heap Corruption

Wed, 08 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Rendering Engine May Enable Remote Heap Corruption

Tue, 07 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Allows Remote Heap Corruption via Crafted HTML

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Allows Remote Heap Corruption via Crafted HTML

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Rendering Engine Enables Remote Heap Corruption

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Rendering Engine Enables Remote Heap Corruption

Sat, 04 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Google Chrome Dawn Rendering Engine Allows Heap Corruption

Sat, 04 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Google Chrome Dawn Rendering Engine Allows Heap Corruption

Sat, 04 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome's Dawn Engine Enables Potential Remote Heap Corruption

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome's Dawn Engine Enables Potential Remote Heap Corruption

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Engine Uninitialized Use Allows Heap Corruption

Thu, 02 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Engine Uninitialized Use Allows Heap Corruption

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Variable in Chrome Dawn Renderer Enables Heap Corruption via Crafted HTML

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Variable in Chrome Dawn Renderer Enables Heap Corruption via Crafted HTML

Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Allows Heap Corruption in Chrome

Wed, 01 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Allows Heap Corruption in Chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-457
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:56:34.556Z

Reserved: 2026-06-29T23:03:26.979Z

Link: CVE-2026-13825

cve-icon Vulnrichment

Updated: 2026-07-01T15:04:40.560Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:30:09Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable