Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19146

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome on Android, specifically within its Graphics Processing Unit (GPU) component. A remote attacker, after compromising the browser's renderer process, could exploit an uninitialized memory vulnerability by tricking a user into visiting a specially crafted HTML page. This could allow the attacker to gain access to potentially sensitive information stored in the browser's memory.

Отчет

This Moderate impact information disclosure flaw affects the Chromium component in Red Hat community projects such as Fedora and EPEL. While initially reported for Google Chrome on Android, the underlying vulnerability in the GPU component could allow a remote attacker, after compromising the renderer process, to obtain sensitive information from process memory by enticing a user to visit a specially crafted HTML page.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2512275chromium-browser: Google Chrome (Android): Information disclosure via uninitialized GPU memory use

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
10 дней назад

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVSS3: 5.3
nvd
10 дней назад

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19146 Uninitialized Use in GPU

CVSS3: 5.3
debian
10 дней назад

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.79 ...

CVSS3: 5.3
github
10 дней назад

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

6.5 Medium

CVSS3