Junglewise Threat Intelligence

CVE-2026-87647: Google Chrome uninitialized resource in GPU

CVE-2026-87647 · Severity: low · CVSS 3.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an uninitialized resource vulnerability in its GPU processing component. An attacker who has already compromised the browser's rendering process could exploit this to read memory outside the browser's security sandbox, potentially exposing sensitive data. This affects users on Windows, Mac, and Linux before version 153.0.8010.36.

Technical details

The vulnerability is an uninitialized resource in the GPU component of Chromium. An attacker who has already achieved code execution in the renderer process can exploit this flaw through a crafted HTML page to read memory from outside the browser's sandbox boundary. While the official Chromium security severity is rated High, the reported CVSS score is 3.4 (low severity), likely due to the requirement for prior renderer process compromise as a prerequisite. The vulnerability was fixed in Chrome version 153.0.8010.36, released in September 2026.

Affected products

  • Google Chrome before 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats