Junglewise Threat Intelligence

CVE-2026-78969: Google Chrome uninitialized resource in Video

CVE-2026-78969 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's video component contained an uninitialized resource that could allow a remote attacker to read memory within Chrome's sandbox by visiting a malicious webpage. This could expose sensitive information processed by the browser, though the attacker remains constrained within the sandbox boundary.

Technical details

The vulnerability is an uninitialized resource in Chrome's Video component that allows an attacker to read memory within the sandbox via a crafted HTML page. The attack requires no user authentication and is triggered by network delivery of a malicious webpage. By exploiting this uninitialized state, an attacker can leak sensitive data from the renderer process memory while remaining confined to the sandbox boundary. The vulnerability was fixed in Chrome version 152.0.7977.65, released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats