Junglewise Threat Intelligence

CVE-2026-78914: Google Chrome uninitialized resource in Skia

CVE-2026-78914 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Skia graphics library contains an uninitialized resource vulnerability that could allow attackers to read memory within the browser sandbox via a specially crafted HTML page. While memory exposure is typically contained by the sandbox, this could leak sensitive data cached in the browser process. The vulnerability was fixed in Chrome 152.0.7977.65.

Technical details

An uninitialized resource in the Skia graphics rendering engine allows remote attackers to potentially read memory within the Chrome sandbox. The vulnerability is triggered by a crafted HTML page that the victim visits; no authentication or special interaction is required beyond standard web browsing. An attacker can leak sensitive data stored in the browser's memory, though impact is somewhat limited by the sandbox boundary. The issue was fixed in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats