Description
Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Untrusted memory read via out-of-bounds GPU access
Action: Apply patch
AI Analysis

Impact

The vulnerability allows a crafted web page to trigger an out-of-bounds read inside the GPU driver of Google Chrome on Android, exposing memory contents that belong to the sandboxed process. This does not provide code execution or write capabilities but can leak sensitive data from the process address space. The weakness is a classic out-of-bounds read condition (CWE-125).

Affected Systems

Google Chrome running on Android devices with a version earlier than 152.0.7977.65 is impacted. The issue is specific to Chrome's GPU handling on Android and does not affect non-Android builds or later versions of the browser.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. The EPSS score is less than 1%, signaling a low likelihood of exploitation in the near term, and the flaw is not listed in CISA’s KEV catalog, so no publicly known exploits exist yet. The vulnerability is triggered by a crafted HTML page, meaning a remote attacker can entice a user to visit a malicious site to activate the out-of-bounds read and leak memory data from Chrome’s sandboxed process.

Generated by OpenCVE AI on August 29, 2026 at 00:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 152.0.7977.65 or later to receive the GPU read‑out‑of‑bounds fix
  • If an update is not possible, consider disabling hardware acceleration in Chrome settings to mitigate the risk of GPU-based memory leaks
  • Ensure Chrome is configured to run in a sandboxed mode and that any device policy restricts execution of GPU processes where possible

Generated by OpenCVE AI on August 29, 2026 at 00:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Out of Bounds GPU Read in Chrome on Android Before 152.0.7977.65

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Out of Bounds GPU Read in Chrome on Android Before 152.0.7977.65

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T19:01:05.033Z

Reserved: 2026-08-25T06:12:20.408Z

Link: CVE-2026-79241

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:18.397

Modified: 2026-08-31T14:03:53.837

Link: CVE-2026-79241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses