Junglewise Threat Intelligence

CVE-2026-79007: Google Chrome uninitialized resource in GPU

CVE-2026-79007 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's GPU rendering component contained an uninitialized memory resource that could allow an attacker with control over the browser's rendering process to read memory outside the security sandbox. An attacker would need to first compromise the renderer process—typically through another vulnerability like a malicious webpage or downloaded file—to exploit this flaw.

Technical details

The vulnerability is an uninitialized resource flaw in Chrome's GPU component. It requires an attacker who has already compromised the renderer process to trigger the bug via a crafted HTML page. The impact is information disclosure: the attacker can read memory outside the sandbox boundary, potentially exposing sensitive data. The vulnerability was patched in Chrome 152.0.7977.65 and later versions. The Chromium project assigned it "Medium" severity despite the low CVSS score of 3.1, reflecting the requirement for a prior renderer compromise.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats