Junglewise Threat Intelligence

CVE-2026-78965: Google Chrome uninitialized resource in ANGLE

CVE-2026-78965 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics library contains an uninitialized resource vulnerability that allows a remote attacker to access cross-origin data through a specially crafted webpage. This could lead to unauthorized access to sensitive information from other websites visited in the same browser, compromising user privacy and potentially exposing authentication tokens or personal data.

Technical details

An uninitialized resource in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome allows remote code execution leading to cross-origin data disclosure. The vulnerability is triggered when a user visits a crafted HTML page, requiring no user interaction beyond the visit itself. The uninitialized resource can be exploited to read memory containing data from other origin contexts, breaking the same-origin policy. The vulnerability was patched in Chrome 152.0.7977.65 and later versions. This is a network-reachable vulnerability with high impact on confidentiality.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats