Description
Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uninitialized resource in the Skia graphics library used by Google Chrome allows a remote attacker to read memory within the browser sandbox by serving a crafted HTML page. The vulnerability exploits improper initialization to expose internal data, potentially leaking sensitive information to the attacker.

Affected Systems

Google Chrome versions prior to 152.0.7977.65 are affected. Users running any earlier stable channel of Chrome are vulnerable; upgrading to 152.0.7977.65 or later mitigates the issue.

Risk and Exploitability

The Chromium security team rated this issue as low severity, the EPSS score is unavailable, and it is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The attack vector requires remote delivery of a malicious HTML page that is opened by a user with Chrome running, and the exploit would read memory inside the sandbox rather than achieving code execution.

Generated by OpenCVE AI on August 25, 2026 at 22:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or newer.
  • Confirm that automatic updates are enabled so future patches are applied promptly.
  • If automatic updates are disabled, download and install version 152.0.7977.65 manually from Google's official website.

Generated by OpenCVE AI on August 25, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-25T20:10:59.988Z

Reserved: 2026-08-25T06:04:09.216Z

Link: CVE-2026-78914

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:48.930

Modified: 2026-08-25T21:17:48.930

Link: CVE-2026-78914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:00:11Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource