CVE-2026-5281-CVE-2026-11057-fullchain

Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

Published 26 Aug 2026Updated 26 Aug 202616 sources
CVSS 6.5 MEDIUMPoC CANDIDATE

Source timeline

Discovered through CVE-IntelView source ↗