Description
Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

Uninitialized Skia resources in Google Chrome versions prior to 152.0.7977.65 allow a remote attacker who has already compromised the renderer process to potentially read data from other browser origins through a specially crafted HTML page. The weakness consists in an inadequate validation of a resource used by the Skia graphics library, which can lead to a confidentiality loss, as defined by the associated CWE-908.

Affected Systems

The vulnerability affects Google Chrome on all platforms for versions earlier than 152.0.7977.65. The issue was identified in the renderer process that draws web content using the Skia library.

Risk and Exploitability

The CVE is not listed in the CISA KEV catalog and the EPSS score is < 1%, indicating a very low exploitation probability. Exploitation requires that the attacker already compromises the renderer process, so the attack vector is a chained attack. The Chromium advisory rates the severity as Medium, as reflected by a CVSS score of 3.1, indicating moderate risk for environments that expose Chrome to untrusted content.

Generated by OpenCVE AI on August 31, 2026 at 16:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later to eliminate the uninitialized Skia resource bug.
  • Confirm that Chrome’s renderer processes are sandboxed and that operating‑system isolation mechanisms are active; this mitigates the impact if a renderer is compromised.
  • Monitor for unusual cross‑origin data requests or anomalous rendering behavior and review any third‑party extensions that may inject custom content.

Generated by OpenCVE AI on August 31, 2026 at 16:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Sat, 05 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: skia: chromium-browser: Uninitialized resource in Skia
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Skia Resource Enables Cross-Origin Data Leak

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Skia Resource Enables Cross-Origin Data Leak

Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-31T13:51:58.831Z

Reserved: 2026-08-25T06:05:05.291Z

Link: CVE-2026-78958

cve-icon Vulnrichment

Updated: 2026-08-31T13:51:54.551Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:51.840

Modified: 2026-08-31T18:59:04.107

Link: CVE-2026-78958

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-25T20:10:13Z

Links: CVE-2026-78958 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:45:03Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource