Junglewise Threat Intelligence

CVE-2026-79270: Google Chrome uninitialized resource in ANGLE

CVE-2026-79270 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics library contained an uninitialized resource vulnerability that could allow an attacker to read memory outside the browser's security sandbox. An attacker could exploit this by tricking a user into viewing a specially crafted webpage, potentially exposing sensitive data or system information.

Technical details

This vulnerability is an uninitialized resource issue in ANGLE (Almost Native Graphics Layer Engine), Chrome's graphics abstraction layer. The flaw allows a remote attacker to read memory outside the browser sandbox via a crafted HTML page. The attack vector is network-based, requiring user interaction (visiting a malicious webpage). An attacker can achieve arbitrary memory disclosure, potentially leaking sensitive information from the process. The vulnerability was patched in Chrome version 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: CVE-2026-79270 disclosed with Chrome 152 release
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats