Junglewise Threat Intelligence

CVE-2026-87576: Google Chrome uninitialized resource in GPU on Android

CVE-2026-87576 · Severity: low · CVSS 3.4 · Published 2026-09-09

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome's GPU component on Android contained an uninitialized resource that allowed attackers who had compromised the renderer process to read memory outside the browser's security sandbox. This could enable data theft or further exploitation, but requires the renderer process to already be compromised as a prerequisite.

Technical details

This vulnerability is an uninitialized resource in Chrome's GPU handling on Android. An attacker who had already compromised the renderer process could exploit this flaw via a crafted HTML page to read memory outside the sandbox. The vulnerability requires prior compromise of the render process and is triggered through web content delivery. The fix was included in Chrome 153.0.8010.36 for Android. Chromium classified this as medium severity.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats