Junglewise Threat Intelligence

CVE-2026-78958: Google Chrome uninitialized resource in Skia

CVE-2026-78958 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an uninitialized resource vulnerability in the Skia graphics library that affects versions prior to 152.0.7977.65. An attacker with an already compromised renderer process could exploit this flaw via a crafted HTML page to potentially access sensitive data from other websites, bypassing the browser's cross-origin protection mechanisms.

Technical details

The vulnerability is an uninitialized resource issue in the Skia graphics rendering engine within Google Chrome. The attack requires an attacker to have already compromised the renderer process, and then deliver a specially crafted HTML page to trigger the uninitialized resource access. Successful exploitation could allow the attacker to obtain cross-origin data that should be isolated between websites. The issue was assigned a Medium severity rating by Chromium security team and a CVSS score of 3.1. A patch is available in Chrome version 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats