Description
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Score: 3.4 Low
EPSS: n/a
KEV: No
Impact: Memory Read Outside Sandbox
Action: Patch
AI Analysis

Impact

An uninitialized GPU resource in Google Chrome on Android allows a crafted HTML page to cause the renderer process to read memory outside its sandbox. The read can expose sensitive user data, representing a confidentiality breach. The flaw is classified as CWE‑908.

Affected Systems

Google Chrome for Android versions prior to 154.0.8037.57 are affected. The vulnerability arises in the GPU component handling rendering. Devices running any earlier build need patching to close this path.

Risk and Exploitability

The attacker must form a malicious HTML page and load it in a browser where the renderer is already compromised, implying a local or partially trusted threat. No public exploit code is documented and the EPSS score is unavailable, but the CVE was assigned medium severity. The issue is not yet listed by CISA in its KEV catalog, reducing known exploit prevalence but still posing a substantial risk when the renderer is subverted.

Generated by OpenCVE AI on September 29, 2026 at 23:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to 154.0.8037.57 or newer on all Android devices.
  • Disable GPU acceleration in Chrome to stop the affected GPU resource from being used.
  • Sanitize or isolate all untrusted HTML content to prevent the renderer from processing malicious pages.

Generated by OpenCVE AI on September 29, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6513-1 chromium security update
History

Wed, 30 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Resource Allows Remote Memory Read in Chrome's GPU on Android chromium-browser: chromium-browser: Uninitialized resource in GPU
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 29 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Resource Allows Remote Memory Read in Chrome's GPU on Android

Tue, 29 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T21:12:11.403Z

Reserved: 2026-09-22T05:10:43.618Z

Link: CVE-2026-95359

cve-icon Vulnrichment

Updated: 2026-09-29T21:07:57.566Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:29.133

Modified: 2026-09-29T22:19:05.333

Link: CVE-2026-95359

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-29T17:31:46Z

Links: CVE-2026-95359 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T23:15:08Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource