Executive brief
Google Chrome's ANGLE graphics library contained an uninitialized resource vulnerability that could allow an attacker to read memory outside the browser's security sandbox. An attacker could exploit this by tricking a user into viewing a specially crafted webpage, potentially exposing sensitive data or system information.
Technical details
This vulnerability is an uninitialized resource issue in ANGLE (Almost Native Graphics Layer Engine), Chrome's graphics abstraction layer. The flaw allows a remote attacker to read memory outside the browser sandbox via a crafted HTML page. The attack vector is network-based, requiring user interaction (visiting a malicious webpage). An attacker can achieve arbitrary memory disclosure, potentially leaking sensitive information from the process. The vulnerability was patched in Chrome version 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79270 disclosed with Chrome 152 release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65