Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6316-1 | chromium security update |
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google android
|
|
| CPEs | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Google android
|
Fri, 29 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Fri, 29 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Uninitialized Use in GPU Exposes Cross‑Origin Data via Render Process Compromise | chromium-browser: Uninitialized Use in GPU |
| Weaknesses | CWE-824 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 29 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Uninitialized Use in GPU Exposes Cross‑Origin Data via Render Process Compromise | |
| First Time appeared |
Google
Google chrome |
|
| Vendors & Products |
Google
Google chrome |
Thu, 28 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| Weaknesses | CWE-457 | |
| References |
|
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2026-05-29T16:25:37.004Z
Reserved: 2026-05-28T17:24:51.425Z
Link: CVE-2026-9920
Updated: 2026-05-29T16:25:34.046Z
Status : Analyzed
Published: 2026-05-28T23:16:50.090
Modified: 2026-06-01T18:48:25.537
Link: CVE-2026-9920
OpenCVE Enrichment
Updated: 2026-05-29T20:45:07Z
Debian DSA