Description
Out of bounds read in Tint in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Update Browser
AI Analysis

Impact

An out‑of‑bounds read bug affects the Tint component in Google Chrome for Android. A maliciously crafted HTML page can trigger the fault, allowing an attacker to read memory located inside the sandboxed renderer process and potentially expose sensitive data. The flaw is classified as CWE‑125, an off‑by‑one error that results in an information‑disclosure vulnerability.

Affected Systems

All Chrome Stable builds for Android older than version 152.0.7977.65 are affected. Devices running those releases should be considered at risk until they apply the patched update.

Risk and Exploitability

The vulnerability requires only a single malicious web page to be loaded in Chrome; no local privilege escalation or code execution is needed. The CVSS score of 6.5 reveals a medium severity, yet with an EPSS score of < 1% and no listing in CISA’s KEV catalog, the likelihood of exploitation presently appears low. However, the data leakage it enables could compromise user privacy. Chromium rates the issue as low severity.

Generated by OpenCVE AI on August 27, 2026 at 19:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome 152.0.7977.65 or newer on all Android devices.
  • Enable Chrome’s auto‑update feature so that future patches are applied automatically.
  • Practice caution when visiting unknown or untrusted web sites, and consider blocking third‑party content that is not essential.

Generated by OpenCVE AI on August 27, 2026 at 19:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in Chrome Android Tint Component Allows Remote Memory Leak
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in Chrome Android Tint Component Allows Remote Memory Leak

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Out of bounds read in Tint in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T15:22:40.893Z

Reserved: 2026-08-25T06:12:18.406Z

Link: CVE-2026-79239

cve-icon Vulnrichment

Updated: 2026-08-27T15:22:35.412Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:18.180

Modified: 2026-08-27T19:04:20.817

Link: CVE-2026-79239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T19:45:03Z

Weaknesses