CVE-2026-19146

Description

A flaw was found in Google Chrome on Android, specifically within its Graphics Processing Unit (GPU) component. A remote attacker, after compromising the browser's renderer process, could exploit an uninitialized memory vulnerability by tricking a user into visiting a specially crafted HTML page. This could allow the attacker to gain access to potentially sensitive information stored in the browser's memory.

Statement

This Moderate impact information disclosure flaw affects the Chromium component in Red Hat community projects such as Fedora and EPEL. While initially reported for Google Chrome on Android, the underlying vulnerability in the GPU component could allow a remote attacker, after compromising the renderer process, to obtain sensitive information from process memory by enticing a user to visit a specially crafted HTML page.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Memory

If the uninitialized pointer is used in a read operation, an attacker might be able to read sensitive portions of memory.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

If the uninitialized pointer references a memory location that is not accessible to the product, or points to a location that is "malformed" (such as NULL) or larger than expected by a read or write operation, then a crash may occur.

Integrity,Confidentiality,Availability

Technical Impact: Execute Unauthorized Code or Commands

If the uninitialized pointer is used in a function call, or points to unexpected data in a write operation, then code execution may be possible.

Frequently Asked Questions

Want to get errata notifications? Sign up here.