Description
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Origin Data Leakage
Action: Apply Patch
AI Analysis

Impact

An uninitialized resource in the ANGLE graphics subsystem of Google Chrome can be exploited by a remote attacker to read cross‑origin data. A maliciously crafted HTML page triggers the flaw, allowing the attacker to bypass the browser's same‑origin policy and obtain information that should be protected. The problem is a type of CWE‑908 vulnerability that exposes data through improper resource handling.

Affected Systems

Google Chrome installations running any version older than 152.0.7977.65 are affected. The issue exists in all desktop builds of the stable channel before that release.

Risk and Exploitability

The vulnerability is remote and requires only an attacker‑controlled HTML page to be loaded in the victim’s browser, meaning that compromised or malicious websites can trigger it. The EPSS score of 0.00244 indicates a very low exploitation probability, and the CVSS score of 4.3 places the flaw in the low to medium severity range. Although it is not currently listed in CISA’s KEV catalog, the flaw allows cross‑origin data leakage which could expose sensitive information. Users should be aware that any web page opened in the affected browser may compromise the confidentiality of data that should be protected by the same‑origin policy.

Generated by OpenCVE AI on August 31, 2026 at 16:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 152.0.7977.65 or later to receive the fix for the uninitialized ANGLE resource.
  • Ensure that the Chrome automatic update feature is enabled so that future vulnerabilities are patched promptly.
  • Limit exposure to potentially malicious web content by reviewing user browsing habits and applying safe‑browsing or content‑filtering solutions that isolate the browser from untrusted origins.

Generated by OpenCVE AI on August 31, 2026 at 16:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Uninitialized ANGLE Resource in Chrome

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Uninitialized ANGLE Resource in Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-31T13:51:29.746Z

Reserved: 2026-08-25T06:09:49.683Z

Link: CVE-2026-79118

cve-icon Vulnrichment

Updated: 2026-08-31T13:51:26.591Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:06.880

Modified: 2026-08-31T15:46:32.093

Link: CVE-2026-79118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:45:03Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource