Junglewise Threat Intelligence

CVE-2026-87642: Google Chrome uninitialized resource in WebGL

CVE-2026-87642 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebGL component contained an uninitialized memory resource that could allow an attacker to leak cross-origin data by crafting a malicious HTML page. This vulnerability could enable an attacker to access sensitive information from other websites, compromising user privacy and data security.

Technical details

An uninitialized resource vulnerability in WebGL's resource handling allowed remote attackers to leak cross-origin data without proper authentication. The vulnerability is triggered by a crafted HTML page served to a victim, making the attack vector network-based with user interaction (visiting a malicious website). The flaw allows an attacker to read sensitive data from other origins, violating the same-origin policy. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87642 publicly disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats