Description
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Disclosure
Action: Update Chrome
AI Analysis

Impact

An uninitialized GPU resource in Google Chrome on Android allows a remote attacker to read memory outside the sandbox by loading a crafted HTML page. The vulnerability exploits the use of an uninitialized resource (CWE‑908) and can expose confidential data, although it does not provide code execution or denial of service. The Chromium severity is low, indicating the impact is limited to confidentiality loss rather than a full system compromise.

Affected Systems

Affected are users running Google Chrome on Android devices with versions earlier than 152.0.7977.65. The flaw resides in the GPU component of the browser and is specific to the Android operating system. Devices with Chrome 151 or lower or earlier builds are susceptible until they upgrade.

Risk and Exploitability

The vulnerability can be exploited remotely by delivering a malicious web page that references the GPU resource; the attack vector is thus a crafted HTML page viewed in the browser. No public exploits are known and the EPSS score is < 1%, so the likelihood of exploitation remains uncertain but is considered low at this time. The flaw is not listed in the CISA KEV catalog, reflecting that it does not pose an immediate exploited risk. Given the CVSS score of 4.3, which indicates a low severity rating, and absence of active exploitation, the risk to typical end users is minimal, but upgrading mitigates the vulnerability immediately.

Generated by OpenCVE AI on August 27, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to 152.0.7977.65 or a later release that includes the GPU resource fix.
  • If a patch cannot be applied immediately, start Chrome with the --disable-gpu flag to prevent GPU acceleration and reduce exposure to the uninitialized resource.
  • Deploy an enterprise policy that blocks or sanitizes potentially malicious web pages and restricts Chrome to a safe browsing configuration to limit the opportunity for an attacker to serve the crafted HTML content.

Generated by OpenCVE AI on August 27, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Uninitialized resource in GPU
References
Metrics threat_severity

None

threat_severity

Low


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Thu, 27 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Uninitialized GPU Resource Allows Memory Disclosure on Android Chrome

Thu, 27 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Uninitialized GPU Resource Allows Memory Disclosure on Android Chrome
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T13:38:31.458Z

Reserved: 2026-08-25T06:08:07.278Z

Link: CVE-2026-79040

cve-icon Vulnrichment

Updated: 2026-08-27T13:38:15.173Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:59.683

Modified: 2026-08-27T19:13:13.593

Link: CVE-2026-79040

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-25T20:10:51Z

Links: CVE-2026-79040 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T16:00:15Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource