Description
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

Uninitialized memory in the ANGLE component of Google Chrome on Windows, before version 155.0.8059.39, can be triggered by a crafted HTML page. This flaw allows a remote attacker to read memory outside the browser sandbox, potentially exposing sensitive data. The Chromium security team labeled the severity as High.

Affected Systems

Any Windows system running Google Chrome prior to version 155.0.8059.39 is affected. The vulnerability is limited to the desktop stable channel and does not impact other Chrome variants or operating systems.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the high CVSS rating and the ability to trigger the exploit via a standard web page make it a serious threat. The most likely attack vector is a malicious website that the user visits; the exploitation requires the victim to open the page in Chrome, after which the attacker can read arbitrary memory.

Generated by OpenCVE AI on October 7, 2026 at 02:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later.
  • Configure Chrome's site‑permission policies or use a browser extension to block loading of potentially malicious content from untrusted origins.
  • Verify that Windows security updates are installed so that the operating system’s sandbox mechanisms remain effective.

Generated by OpenCVE AI on October 7, 2026 at 02:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Title Remote Attacker Read Memory via Uninitialized ANGLE Resource in Chrome

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:09.954Z

Reserved: 2026-10-06T16:31:10.284Z

Link: CVE-2026-106202

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:46.493

Modified: 2026-10-06T19:58:37.060

Link: CVE-2026-106202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:15:12Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource