Junglewise Threat Intelligence

CVE-2026-87497: Google Chrome uninitialized resource in Codecs

CVE-2026-87497 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's codec processing component contained an uninitialized memory resource that allowed attackers to read sensitive data from within the browser sandbox by visiting a malicious webpage. This information disclosure could expose user data or assist in bypassing security protections.

Technical details

An uninitialized resource vulnerability in the Codecs component of Google Chrome allows a remote attacker to read memory inside the Chrome sandbox. The vulnerability is triggered via a crafted HTML page and requires only that a user visit a malicious website—no authentication or user interaction beyond normal browsing is required. The attack vector is network-based. An attacker can achieve information disclosure by reading sensitive data from the sandboxed process memory. The vulnerability was patched in Chrome version 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats