Junglewise Threat Intelligence

CVE-2026-79118: Google Chrome uninitialized resource in ANGLE

CVE-2026-79118 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a vulnerability in its ANGLE graphics rendering library that could allow an attacker to access sensitive data across different websites. An attacker could craft a malicious webpage that exploits this flaw to view private information from other websites the user has visited. While Chrome's sandbox limits the direct harm, this represents a meaningful breach of web security boundaries that protect user privacy.

Technical details

An uninitialized resource vulnerability exists in Google Chrome's ANGLE (Almost Native Graphics Layer Engine) library prior to version 152.0.7977.65. The vulnerability occurs when ANGLE fails to properly initialize a graphics-related resource, leaving it containing stale or sensitive data from other processes or websites. An unauthenticated remote attacker can exploit this via a crafted HTML page served over the network; no user interaction beyond visiting the malicious page is required. Successful exploitation allows the attacker to read cross-origin data (information from other websites), bypassing the Same-Origin Policy that normally prevents this. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: CVE-2026-79118 disclosed in Chrome 152 stable release notes
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats