Description
Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote memory disclosure
Action: Patch
AI Analysis

Impact

An uninitialized GPU resource in Google Chrome for Android before version 153.0.8010.36 permits a remote attacker to read memory outside the sandbox by loading a specially crafted HTML page. The attacker can expose the contents of the device’s memory, potentially revealing sensitive information such as passwords, cryptographic keys, or personal data. This flaw is an example of a memory disclosure vulnerability and is listed under CWE-908.

Affected Systems

Google Chrome running on Android devices that have a version earlier than 153.0.8010.36. Devices using the stable channel prior to the September 2026 update remain vulnerable. No specific manufacturer or operating system level is mentioned beyond the Android platform.

Risk and Exploitability

The vulnerability can be leveraged remotely by any entity that can serve a malicious web page to the target device. The exploit has a CVSS score of 4.7, indicating medium severity, an EPSS score of <1%, and it is not listed in the CISA KEV catalog. Given the lack of a known exploit in the wild, the risk remains moderate, but the flaw provides a direct path to read confidential data from the sandboxed environment.

Generated by OpenCVE AI on September 9, 2026 at 22:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or higher on all Android devices.
  • Ensure the device’s Chrome application has received the latest update from the Google Play Store or the system updater.
  • If an update cannot be applied immediately, disable GPU acceleration by enabling the “Disable hardware acceleration” flag in Chrome’s internal settings to mitigate the risk temporarily.

Generated by OpenCVE AI on September 9, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Uninitialized GPU Resource Memory Disclosure via Crafted HTML Page

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Google chrome
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 09 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Uninitialized GPU Resource Memory Disclosure via Crafted HTML Page

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T17:52:42.410Z

Reserved: 2026-09-08T22:40:29.321Z

Link: CVE-2026-87555

cve-icon Vulnrichment

Updated: 2026-09-09T19:58:06.736Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:13.117

Modified: 2026-09-09T20:24:45.720

Link: CVE-2026-87555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:15:17Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource