Junglewise Threat Intelligence

CVE-2026-78984: Google Chrome uninitialized resource in GPU

CVE-2026-78984 · Severity: low · CVSS 3.4 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's graphics processing unit (GPU) component contained an uninitialized memory resource that could be exploited by an attacker who had already compromised the browser's rendering engine. This vulnerability could allow such an attacker to read sensitive data from memory locations outside the browser's security sandbox, potentially exposing user data or system information.

Technical details

The vulnerability is an uninitialized resource bug in Chrome's GPU component (CVE-2026-78984). An attacker who had already achieved renderer process compromise could exploit this via a crafted HTML page to potentially read memory outside the sandbox boundary. The attack requires a prior renderer compromise (post-compromise vulnerability), and the severity is rated Low with a CVSS score of 3.4. The fix was included in Chrome version 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65

References

Related threats