Description
Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an uninitialized use of a codec component that can cause sensitive data to be read from process memory. The flaw allows a crafted HTML page accessed by a remote attacker to trigger the code path that reads uninitialized memory, potentially leaking confidential data. The weakness, identified as CWE-457, leads to information disclosure affecting the confidentiality of the system.

Affected Systems

Google Chrome users on Windows with versions earlier than 150.0.7871.47 are affected. The vulnerability manifests when a user loads a malicious HTML page in Chrome. No other operating systems or browsers are listed as affected.

Risk and Exploitability

The vulnerability can be exploited remotely by delivering a crafted HTML page to a victim’s browser. Because the exploitation requires the user to open that page, the likelihood of widespread attacks is moderate. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog, so there is no publicly confirmed exploitation. The CVSS score is not provided, but the medium Chromium severity suggests a moderate impact.

Generated by OpenCVE AI on July 1, 2026 at 01:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47 or later.
  • If an upgrade is not immediately possible, avoid browsing untrusted or unknown websites that could deliver malicious HTML pages.
  • Configure Chrome to block or restrict custom-built HTML content through settings or extensions until the vulnerability is patched.

Generated by OpenCVE AI on July 1, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Codecs Exposes Sensitive Data in Chrome on Windows

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-457
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:24:07.181Z

Reserved: 2026-06-29T23:04:01.729Z

Link: CVE-2026-13958

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T01:30:17Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable