Executive brief
Google Chrome's graphics processing unit (GPU) component contains an information leak vulnerability that allows attackers to extract sensitive cross-origin data by crafting malicious web pages. Affected users could have their data from other websites or applications exposed without authorization, potentially compromising account credentials, financial information, or other sensitive content.
Technical details
The vulnerability is an information leak in Chrome's GPU component that allows a remote attacker to obtain cross-origin data via a specially crafted HTML page. The attack vector is network-based with no authentication required, and the user only needs to visit or be directed to the malicious webpage. An attacker can leverage GPU memory access or rendering pipeline flaws to read data that should be isolated between different security origins. Google patched this issue in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux), released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65 (Windows/Mac) and prior to 152.0.7977.64 (Linux)
Timeline
- 2026-08-25: disclosed: Chrome 152 stable release with security fix
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)