Description
Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 3.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Apply patch
AI Analysis

Impact

The CVSS score is 3.4, however the Chromium security team has classified this vulnerability as High, indicating significant risk. The flaw originates from an uninitialized GPU resource in Google Chrome. A remote attacker who has already compromised the renderer process can use a crafted webpage to trigger Chrome to read memory outside the sandbox, leaking data from other processes.

Affected Systems

Affected devices run any version of Google Chrome prior to 153.0.8010.36 on the desktop stable channel. The flaw does not affect Chrome versions 153.0.8010.36 and newer, which contain the applied fix.

Risk and Exploitability

The Chromium security severity assessment assigns this vulnerability a High rating, highlighting the potential for serious information disclosure. The EPSS score of < 1% indicates a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. The required privilege level is the compromised renderer process, and the attacker must supply a malicious webpage. When those conditions are met, the attacker can read arbitrary memory, enabling further compromise such as credential theft or data exfiltration.

Generated by OpenCVE AI on September 9, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Google Chrome version 153.0.8010.36 or later
  • Temporarily disable GPU acceleration by launching Chrome with the --disable-gpu flag or configuring system hardware acceleration to off
  • If operating in an enterprise environment, enforce an admin policy that blocks hardware acceleration to mitigate the risk while a patch is pending

Generated by OpenCVE AI on September 9, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title GPU Uninitialized Resource Remote Memory Disclosure in Chrome

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 09 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title GPU Uninitialized Resource Remote Memory Disclosure in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T19:07:04.953Z

Reserved: 2026-09-08T22:43:59.670Z

Link: CVE-2026-87647

cve-icon Vulnrichment

Updated: 2026-09-09T19:59:19.864Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:23.183

Modified: 2026-09-09T20:28:46.967

Link: CVE-2026-87647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T11:00:09Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource