Junglewise Threat Intelligence

CVE-2026-78986: Google Chrome uninitialized resource in GPU

CVE-2026-78986 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's GPU rendering engine contained an uninitialized memory resource that could allow an attacker with control of the renderer process to access sensitive data from other websites. An attacker could exploit this via a malicious HTML page to steal cross-origin information, such as data from other tabs or sensitive web content.

Technical details

This vulnerability is an uninitialized resource flaw in Chrome's GPU component affecting versions prior to 152.0.7977.65. The vulnerability requires an attacker to have already compromised the renderer process, making it a post-compromise escalation vulnerability. By crafting a malicious HTML page, an attacker can read uninitialized GPU memory to potentially obtain data from other security origins (cross-origin data). The fix is available in Chrome 152.0.7977.65 and later. This was assigned Chromium security severity of High.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats