Junglewise Threat Intelligence

CVE-2026-79221: Google Chrome uninitialized resource in Dawn

CVE-2026-79221 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users to access websites and online applications. A vulnerability in Chrome's Dawn graphics component could allow an attacker to read memory contents within the browser's security sandbox by serving a specially crafted web page, potentially exposing sensitive data to unauthorized access.

Technical details

An uninitialized resource vulnerability exists in the Dawn graphics API component of Google Chrome versions prior to 152.0.7977.65. The vulnerability is triggered when Chrome processes a malicious HTML page, leaving memory uninitialized and accessible to attackers within the sandbox. The attack requires only network access and user interaction (visiting a webpage), with no additional authentication needed. An attacker can potentially read sensitive memory contents within the sandbox environment. The vulnerability is patched in Chrome 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats