Description
Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

An uninitialized GPU resource in Google Chrome on Android allows a compromised renderer process to read memory outside the sandbox through a crafted HTML page. The vulnerability exploits a flaw in the way GPU memory is allocated and initialized, permitting the attacker to access data that should remain isolated to the renderer. The primary consequence is the potential for sensitive information disclosure, which could be leveraged if additional exploitation paths are available. The Chrome security team has rated the issue as medium severity, indicating the risk is significant but not immediate catastrophic.

Affected Systems

All Android users running Google Chrome versions earlier than 155.0.8059.39 are affected. The vulnerability resides in the GPU code that interfaces with the renderer process; any device that installs the affected Chrome build on Android is within scope. Versions 155.0.8059.39 and later contain the remediation.

Risk and Exploitability

The CVE has no EPSS data and is not listed in CISA’s KEV catalog, suggesting limited public exploitation. However, the vulnerability requires an attacker to have already compromised the renderer process, which typically demands a successful drive‑by or phishing attack. The medium severity rating reflects the potential impact on information confidentiality, while the lack of public exploit signatures mitigates immediate risk, yet the possibility remains for targeted exploitation in the future.

Generated by OpenCVE AI on October 7, 2026 at 01:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome on Android to version 155.0.8059.39 or newer, which patches the GPU initialization flaw.
  • As a temporary workaround, disable GPU hardware acceleration in Chrome by navigating to chrome://settings/system and turning off "Use hardware acceleration when available" until the patch is applied.
  • If an immediate update is unavailable, consider uninstalling Chrome or switching to an alternate browser that does not contain the affected code until a patch is installed.

Generated by OpenCVE AI on October 7, 2026 at 01:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 01:30:00 +0000

Type Values Removed Values Added
Title GPU Uninitialized Resource Enables Remote Memory Read via Crafted HTML

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:24.258Z

Reserved: 2026-10-06T16:36:45.111Z

Link: CVE-2026-106370

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:06.080

Modified: 2026-10-06T19:57:00.457

Link: CVE-2026-106370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:30:10Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource