Description
Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Read memory inside the sandbox via crafted HTML
Action: Apply Patch
AI Analysis

Impact

Uninitialized resources in the Dawn graphics driver of Google Chrome prior to version 152.0.7977.65 let a remote attacker craft an HTML document that could read sensitive data from memory that resides inside the sandbox. The flaw is a misuse of uninitialized memory (CWE‑908) and can lead to accidental disclosure of user data or potentially facilitate further exploitation. Confidentiality is at risk if the memory contains sensitive material.

Affected Systems

The vulnerability affects Google Chrome browsers running versions before 152.0.7977.65. Systems using any earlier Chrome build are susceptible.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. The EPSS score is <1%, indicating a very low exploitation probability. The flaw can be triggered by a remote web page loaded into Chrome, allowing an attacker to read memory that resides inside the sandbox. It does not require local privileges, and the primary impact is potential disclosure of sensitive data.

Generated by OpenCVE AI on August 28, 2026 at 23:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Chrome installations to version 152.0.7977.65 or newer.
  • Ensure Chrome updates are automatically applied on all devices and enforce the latest version through user‑management policies.
  • Consider disabling WebGL or the Dawn graphics backend in environments where exposure to malicious web content is a concern, or monitor for suspicious web pages that may trigger the vulnerability.

Generated by OpenCVE AI on August 28, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Sandbox Memory Read via Uninitialized Resource in Chrome Dawn

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Sandbox Memory Read via Uninitialized Resource in Chrome Dawn

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T17:56:47.187Z

Reserved: 2026-08-25T06:11:52.367Z

Link: CVE-2026-79221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:16.197

Modified: 2026-08-31T14:11:13.087

Link: CVE-2026-79221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:15:04Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource