Junglewise Threat Intelligence

CVE-2026-78977: Google Chrome uninitialized resource in GPU on Android

CVE-2026-78977 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that handles web pages and applications. An uninitialized memory resource in the GPU processing component could allow an attacker to read sensitive data from the browser's memory sandbox by hosting a malicious HTML page, potentially exposing user data or internal browser state without requiring any special user interaction beyond normal browsing.

Technical details

This vulnerability is an uninitialized resource issue in the GPU component of Google Chrome on Android. The flaw allows a remote attacker to read memory within the browser's sandbox by crafting a malicious HTML page; the attacker can trigger GPU processing of the crafted content, which may access uninitialized memory regions and leak sensitive data. No special privileges or prior authentication are required—only network reachability to serve the HTML page. The vulnerability affects Chrome on Android versions prior to 152.0.7977.65. Google has fixed the issue in Chrome 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed

References

Related threats