Junglewise Threat Intelligence

CVE-2026-79120: Google Chrome uninitialized resource in ANGLE

CVE-2026-79120 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics library contains an uninitialized resource that could allow a remote attacker to access sensitive data across different websites through a malicious HTML page. An attacker could potentially view or extract data from other websites that the user has open, compromising user privacy and data confidentiality.

Technical details

A use-of-uninitialized-resource vulnerability exists in ANGLE (Almost Native Graphics Layer Engine), Google Chrome's graphics abstraction layer. The flaw allows a remote attacker to read uninitialized memory through a crafted HTML page, potentially accessing cross-origin data. The vulnerability is triggered via network-based attack vector by serving malicious HTML to the victim. ANGLE is part of Chrome's rendering pipeline and is accessible from web content, making the attack surface significant. The vulnerability was fixed in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Windows, Mac, and Linux

References

Related threats