Description
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Unauthorized Memory Read
Action: Immediate Patch
AI Analysis

Impact

An uninitialized resource in ANGLE inside Google Chrome versions prior to 152.0.7977.65 allows a remote attacker who has already compromised the renderer process to read memory outside the sandbox, using a crafted HTML page. This flaw results in memory disclosure and could expose sensitive data that is not protected by the renderer sandbox. The vulnerability is categorized as a medium severity issue in Chromium security terms.

Affected Systems

The affected product is Google Chrome on desktop platforms. Versions before 152.0.7977.65, which are actively delivered to users via the stable channel, are susceptible. Any environment that delivers the pre‑152 build without immediate patching will be exposed.

Risk and Exploitability

The requirement of renderer process compromise represents a prerequisite for exploitation; an attacker must first bypass regular content sandbox checks or achieve code execution in the renderer. Once that condition is met, the memory leak is straightforward to trigger. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no current public exploitation evidence. The CVSS score is 6.5, reflecting a medium severity that aligns with the Chromium severity assessment, and indicates that mitigation should be addressed promptly.

Generated by OpenCVE AI on August 28, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later to obtain the ANGLE initialization fix
  • Ensure that Chrome sandboxing is enabled and that no vendor or policy settings disable or weaken it
  • Continuously monitor for anomalous memory access patterns or renderer process compromises through logging and automated security tooling

Generated by OpenCVE AI on August 28, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Memory Read via Uninitialized ANGLE Resource in Chrome

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Memory Read via Uninitialized ANGLE Resource in Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:15:19.490Z

Reserved: 2026-08-25T06:12:03.858Z

Link: CVE-2026-79229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:17.080

Modified: 2026-08-31T13:34:10.087

Link: CVE-2026-79229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:00:14Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource