Junglewise Threat Intelligence

CVE-2026-79229: Google Chrome uninitialized resource in ANGLE

CVE-2026-79229 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics renderer contains an uninitialized memory resource that allows attackers with a compromised renderer process to read sensitive memory outside the browser's security sandbox. An attacker could exploit this via a malicious HTML page to potentially access protected data in adjacent process memory.

Technical details

CVE-2026-79229 is an uninitialized resource vulnerability in ANGLE (Almost Native Graphics Layer Engine), Google Chrome's graphics rendering library. The vulnerability allows an attacker who has already compromised the renderer process to escape the sandbox and read memory from other processes via a crafted HTML page. The attack requires prior renderer process compromise and ability to serve malicious web content. A patch was released in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux). This is tracked as a medium-severity issue by Chromium security.

Affected products

  • Google Chrome prior to 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

References

Related threats