Executive brief
Google Chrome's ANGLE graphics engine contains an uninitialized resource vulnerability that could allow an attacker to bypass web origin policy protections. An attacker could craft a malicious HTML page to exploit this flaw, potentially enabling unauthorized access to content from other websites or cross-site attacks. This affects Chrome versions prior to 152.0.7977.65 on Windows, Mac, and Linux.
Technical details
The vulnerability is an uninitialized resource flaw in ANGLE (Almost Native Graphics Layer Engine), Chrome's cross-platform graphics abstraction layer. The vulnerability allows a remote attacker to bypass Same-Origin Policy (SOP) restrictions through a crafted HTML page, without requiring user authentication or special preconditions beyond visiting the malicious page. The attack vector is network-based and relies on browser rendering of attacker-controlled HTML. Google patched this issue in Chrome 152.0.7977.65, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79269 disclosed in Chrome 152 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65