Executive brief
Google Chrome's WebGL component contained an uninitialized memory resource that could allow an attacker to leak cross-origin data by crafting a malicious HTML page. This vulnerability could enable an attacker to access sensitive information from other websites, compromising user privacy and data security.
Technical details
An uninitialized resource vulnerability in WebGL's resource handling allowed remote attackers to leak cross-origin data without proper authentication. The vulnerability is triggered by a crafted HTML page served to a victim, making the attack vector network-based with user interaction (visiting a malicious website). The flaw allows an attacker to read sensitive data from other origins, violating the same-origin policy. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed: CVE-2026-87642 publicly disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36