Description
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑origin Data Exposure
Action: Update
AI Analysis

Impact

An uninitialized GPU resource in Google Chrome prior to version 152.0.7977.65 permits a remote attacker who has already compromised the renderer process to read data belonging to other web origins through a specially crafted HTML page. The flaw is a form of improper resource initialization (CWE‑908) that can leak confidential content from sandboxed renderer processes.

Affected Systems

All installations of Google Chrome before update 152.0.7977.65 are vulnerable, regardless of operating system, as the issue resides in the GPU handling code within the renderer process of the Chrome browser.

Risk and Exploitability

The flaw carries a Chromium‑rated high severity, but the CVSS score of 3.1 indicates a low overall severity. Its EPSS score is less than 1%, suggesting a very low probability of exploitation. An attacker must first succeed in compromising the renderer process, after which they can potentially exfiltrate cross‑origin data. Although the risk of initial compromise depends on other software bugs, once achieved the data leakage could occur without further action by the attacker.

Generated by OpenCVE AI on August 31, 2026 at 15:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Chrome update to version 152.0.7977.65 or later.
  • Disable GPU hardware acceleration in Chrome’s settings to reduce use of the vulnerable resource while a patch is pending.
  • Ensure Chrome’s sandboxing and process isolation are enabled to limit the impact of any renderer compromise.

Generated by OpenCVE AI on August 31, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Exposure via Uninitialized GPU Resource in Google Chrome

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Exposure via Uninitialized GPU Resource in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-31T13:45:29.112Z

Reserved: 2026-08-25T06:06:46.796Z

Link: CVE-2026-78986

cve-icon Vulnrichment

Updated: 2026-08-31T13:45:25.512Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:54.970

Modified: 2026-08-31T15:04:03.677

Link: CVE-2026-78986

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:00:06Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource