Description
Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote memory disclosure via crafted web page
Action: Patch immediately
AI Analysis

Impact

A flaw in the Dawn rendering engine of Google Chrome on macOS allows a remote attacker to read memory beyond the sandbox boundaries. The vulnerability results from an uninitialized resource that can be exploited by delivering a specially crafted HTML page to the user. This permits the attacker to access sensitive data stored in the renderer process, potentially compromising confidentiality. The weakness corresponds to CWE-908: Uninitialized Resource.

Affected Systems

Affected systems are macOS users running Google Chrome before version 155.0.8059.39. The issue exists in Chrome’s Desktop channel on macOS; the advisory references the stable channel update to 155.0.8059.39 that addresses the uninitialized Dawn resource.

Risk and Exploitability

No CVSS score is provided but the security advisory classifies it as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is a malicious web page loaded in the browser; the attacker must convince the user to visit the page. Once the page loads, the renderer can read arbitrary memory, giving the attacker the ability to exfiltrate confidential information.

Generated by OpenCVE AI on October 7, 2026 at 03:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on macOS to version 155.0.8059.39 or later as released by Google.
  • If an immediate update is not feasible, block or restrict access to untrusted websites via network filtering or Chrome enterprise policies to prevent the delivery of crafted HTML pages.
  • Enable Chrome’s Safe Browsing feature and enforce strict site reputation checks to detect and block malicious content before it can be rendered.

Generated by OpenCVE AI on October 7, 2026 at 03:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 03:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Dawn Resource Enables Remote Memory Disclosure on macOS Chrome

Wed, 07 Oct 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:09.797Z

Reserved: 2026-10-06T16:32:22.835Z

Link: CVE-2026-106231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:49.913

Modified: 2026-10-06T19:58:37.060

Link: CVE-2026-106231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:15:08Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource