Name CVE-2026-7924 Description Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) Source CVE (at NVD ; CERT , ENISA , LWN , oss-sec , fulldisc , Debian ELTS , Red Hat , Ubuntu , Gentoo , SUSE bugzilla /CVE , GitHub advisories /code /issues , web search , more )References DSA-6250-1
Vulnerable and fixed packages The table below lists information on source packages.
Source Package Release Version Status chromium (PTS )bullseye (security), bullseye 120.0.6099.224-1~deb11u1 vulnerable bookworm 143.0.7499.169-1~deb12u1 vulnerable bookworm (security) 148.0.7778.96-1~deb12u1 fixed trixie 145.0.7632.159-1~deb13u1 vulnerable trixie (security) 148.0.7778.96-1~deb13u1 fixed forky 147.0.7727.137-1 vulnerable sid 148.0.7778.96-3 fixed
The information below is based on the following data on fixed versions.
Notes [bullseye] - chromium <end-of-life> (see #1061268)