Description
Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uninitialized use flaw exists in Chrome’s Dawn rendering engine that lets a crafted HTML page cause the engine to read contents of uninitialized memory. The vulnerability is classified as CWE‑457 and has a medium severity rating of 6.5 on the CVSS score scale. It permits only the acquisition of potentially sensitive data from the browser process; no code execution or privilege escalation can be achieved by the attacker.

Affected Systems

All desktop installations of Google Chrome earlier than version 150.0.7871.46 are affected. The June 2026 stable channel update to 150.0.7871.46 contains the fix, and any desktop deployment still running an older build remains at risk.

Risk and Exploitability

The EPSS score is below 1 %, indicating a very low likelihood that this vulnerability will be actively exploited. It is not listed in the CISA KEV catalog. An attacker must serve a maliciously crafted HTML page that is rendered by the vulnerable Chrome instance; no local system privileges or additional attack steps are required.

Generated by OpenCVE AI on July 31, 2026 at 15:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome 150.0.7871.46 through your organization’s update distribution system as soon as possible.
  • If patching cannot be undertaken immediately, harden the browser environment by enforcing stricter sandboxing or disabling features that expose memory contents to web content.
  • Continuously monitor browser activity for anomalous memory access or unusual page load patterns that could indicate exploitation.

Generated by OpenCVE AI on July 31, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome’s Dawn Engine Causes Browser Memory Disclosure

Mon, 27 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome’s Dawn Engine Causes Browser Memory Disclosure

Tue, 21 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Enables Remote Information Disclosure

Thu, 16 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Enables Remote Information Disclosure

Tue, 14 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Engine Enables Remote Information Disclosure

Mon, 13 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Engine Enables Remote Information Disclosure

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Engine Enables Remote Information Disclosure

Sat, 11 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Engine Enables Remote Information Disclosure

Fri, 10 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome’s Dawn Engine Enables Remote Information Disclosure

Thu, 09 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome’s Dawn Engine Enables Remote Information Disclosure

Wed, 08 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Allows Remote Information Disclosure in Google Chrome

Wed, 08 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Allows Remote Information Disclosure in Google Chrome

Tue, 07 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use Vulnerability in Chrome Dawn Enables Remote Information Disclosure

Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use Vulnerability in Chrome Dawn Enables Remote Information Disclosure

Mon, 06 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Uninitialized Use in Chrome's Dawn Engine

Sun, 05 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Uninitialized Use in Chrome's Dawn Engine

Sun, 05 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome Dawn Allows Remote Information Disclosure

Sat, 04 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome Dawn Allows Remote Information Disclosure

Sat, 04 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome's Dawn Rendering Engine Allows Information Disclosure

Fri, 03 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome's Dawn Rendering Engine Allows Information Disclosure

Fri, 03 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome's Dawn Rendering Engine Enables Remote Information Disclosure

Thu, 02 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome's Dawn Rendering Engine Enables Remote Information Disclosure

Thu, 02 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome Dawn Enabling Remote Information Disclosure

Thu, 02 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome Dawn Enabling Remote Information Disclosure

Thu, 02 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-457
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T00:31:01.602Z

Reserved: 2026-07-01T21:37:28.255Z

Link: CVE-2026-14399

cve-icon Vulnrichment

Updated: 2026-07-02T00:30:57.792Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T15:30:03Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable