Junglewise Threat Intelligence

CVE-2026-79285: Google Chrome uninitialized resource in ANGLE

CVE-2026-79285 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's ANGLE graphics library contains an uninitialized resource vulnerability on Windows that could allow an attacker to read sensitive data from other websites. By crafting a malicious HTML page, a remote attacker could exploit this flaw to access cross-origin data, bypassing the browser's security boundaries that keep websites isolated from each other.

Technical details

An uninitialized resource exists in ANGLE (Almost Native Graphics Layer Engine), Google Chrome's graphics abstraction layer used on Windows. The vulnerability allows a remote attacker to read cross-origin data via a crafted HTML page—a typical web-based attack requiring no special authentication or local access. The vulnerability was assigned CVE-2026-79285 with a CVSS score of 6.5 (Medium severity). The fix was included in Chrome 152.0.7977.65 for Windows and Mac (152.0.7977.64 for Linux), released on August 25, 2026. Users running earlier versions remain exposed to information disclosure attacks.

Affected products

  • Google Chrome prior to 152.0.7977.65 (Windows/Mac), prior to 152.0.7977.64 (Linux)

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats