Description
Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 3.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

Google Chrome on Android before version 153.0.8010.36 uses an uninitialized GPU resource that can be accessed by a renderer process that has already been compromised. A malicious site can craft an HTML page that causes the renderer to read memory outside the sandbox, exposing sensitive data such as cookies or credential information. This flaw is a memory disclosure vulnerability and allows attackers to bypass process isolation that is intended to protect user data.

Affected Systems

The affected product is Google Chrome for Android, specifically any installation older than version 153.0.8010.36. All Android devices running these older Chrome builds are vulnerable; other browsers or vendors are not listed.

Risk and Exploitability

The CVSS score of 3.4 and an EPSS score of less than 1% indicate a moderate severity with a very low but non‑zero likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. Exploitation requires the renderer process to be already compromised and a crafted web page to be delivered, limiting the attack surface to remote web content. Although the risk of exploitation is low, memory disclosure still poses a potential impact to user confidentiality.

Generated by OpenCVE AI on September 9, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 153.0.8010.36 or newer.
  • If an upgrade cannot be performed immediately, disable GPU acceleration in Chrome settings to limit the attack surface.
  • Avoid loading untrusted web content or consider using a sandboxed browser environment for sensitive browsing activity.

Generated by OpenCVE AI on September 9, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title GPU Resource Leak Enables Memory Read in Chrome for Android

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Google chrome

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 09 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title GPU Resource Leak Enables Memory Read in Chrome for Android

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T19:06:49.522Z

Reserved: 2026-09-08T22:41:09.495Z

Link: CVE-2026-87576

cve-icon Vulnrichment

Updated: 2026-09-09T19:46:54.051Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:15.387

Modified: 2026-09-09T20:28:34.350

Link: CVE-2026-87576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:45:05Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource