Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76042

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 6.8

Описание

Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome, specifically within its GPU component, where an uninitialized resource could be used. A remote attacker, after compromising the renderer process, could exploit this by crafting a malicious HTML page. This could allow the attacker to read memory outside of the browser's security sandbox, leading to information disclosure.

Отчет

This Moderate impact information disclosure flaw in Chromium and QtWebEngine, affecting community projects, requires a prior renderer process compromise and user interaction with a specially crafted HTML page. The need for these preconditions reduces the overall risk in typical Red Hat desktop deployments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2518271chromium-browser: Google Chrome: Information disclosure via uninitialized resource in GPU

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
29 дней назад

Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 3.1
nvd
около 1 месяца назад

Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
28 дней назад

Chromium: CVE-2026-76042 Use of uninitialized resource in GPU

CVSS3: 3.1
debian
около 1 месяца назад

Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7 ...

CVSS3: 3.1
github
около 1 месяца назад

Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

6.8 Medium

CVSS3