CVE-2026-19146
Description
A flaw was found in Google Chrome on Android, specifically within its Graphics Processing Unit (GPU) component. A remote attacker, after compromising the browser's renderer process, could exploit an uninitialized memory vulnerability by tricking a user into visiting a specially crafted HTML page. This could allow the attacker to gain access to potentially sensitive information stored in the browser's memory.
Statement
This Moderate impact information disclosure flaw affects the Chromium component in Red Hat community projects such as Fedora and EPEL. While initially reported for Google Chrome on Android, the underlying vulnerability in the GPU component could allow a remote attacker, after compromising the renderer process, to obtain sensitive information from process memory by enticing a user to visit a specially crafted HTML page.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Memory
If the uninitialized pointer is used in a read operation, an attacker might be able to read sensitive portions of memory.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
If the uninitialized pointer references a memory location that is not accessible to the product, or points to a location that is "malformed" (such as NULL) or larger than expected by a read or write operation, then a crash may occur.
Integrity,Confidentiality,Availability
Technical Impact: Execute Unauthorized Code or Commands
If the uninitialized pointer is used in a function call, or points to unexpected data in a write operation, then code execution may be possible.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.