Description
Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uninitialized variable in the Dawn rendering engine of Google Chrome on ChromeOS allows a remote attacker, via a crafted HTML page, to read data from the browser's process memory. The flaw, classified as CWE-457, results in the disclosure of potentially sensitive information without requiring authentication, leading to confidentiality loss.

Affected Systems

Google Chrome on ChromeOS versions earlier than 150.0.7871.46 are affected. Devices running these builds remain vulnerable until they receive the patched release from Google.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5 and an EPSS score of less than 1%. This indicates a medium severity but a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to deliver and render malicious HTML to potentially glean sensitive data.

Generated by OpenCVE AI on July 21, 2026 at 12:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.46 or later, ensuring the updated Dawn engine is in use.
  • Restart the browser or the operating system after applying the update so that the new code paths are activated.
  • Enable automatic updates on ChromeOS so that future security patches are applied without manual intervention.

Generated by OpenCVE AI on July 21, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Variable in Chrome Dawn Allows Information Disclosure via Malicious HTML

Wed, 15 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Engine Allows Remote Memory Disclosure

Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome Dawn Engine Allows Remote Memory Disclosure

Mon, 13 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Engine Uninitialized Variable Enables Remote Information Disclosure

Mon, 13 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Engine Uninitialized Variable Enables Remote Information Disclosure

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Variable in ChromeOS Dawn Rendering Engine Enables Remote Information Disclosure

Sat, 11 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Variable in ChromeOS Dawn Rendering Engine Enables Remote Information Disclosure

Fri, 10 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome's Dawn Engine Enables Browser Memory Disclosure

Thu, 09 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome's Dawn Engine Enables Browser Memory Disclosure

Wed, 08 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome's Dawn Rendering Engine Allows Remote Information Disclosure

Tue, 07 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Chrome's Dawn Rendering Engine Allows Remote Information Disclosure

Mon, 06 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Dawn Variable Enables Browser Memory Disclosure via Crafted HTML

Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Dawn Variable Enables Browser Memory Disclosure via Crafted HTML

Sun, 05 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Allows Remote Process Memory Disclosure on ChromeOS

Sat, 04 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in Dawn Rendering Engine Allows Remote Process Memory Disclosure on ChromeOS

Sat, 04 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome Dawn Engine Allows Memory Disclosure

Sat, 04 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome Dawn Engine Allows Memory Disclosure

Fri, 03 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Variable in Chrome Rendering Engine Enables Remote Information Disclosure

Thu, 02 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Variable in Chrome Rendering Engine Enables Remote Information Disclosure

Thu, 02 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Variable in Chrome Dawn Enables Remote Information Disclosure

Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Variable in Chrome Dawn Enables Remote Information Disclosure

Thu, 02 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-457
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T00:31:27.782Z

Reserved: 2026-07-01T21:37:33.334Z

Link: CVE-2026-14421

cve-icon Vulnrichment

Updated: 2026-07-02T00:31:23.667Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:00:04Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable