Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78914

Опубликовано: 25 авг. 2026
Источник: redhat
EPSS Низкий

Описание

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

A flaw was found in Skia, a 2D graphics library used in Chromium. A remote attacker could exploit an uninitialized resource vulnerability by tricking a user into opening a specially crafted HTML page. This could potentially allow the attacker to read sensitive memory within the browser's sandbox, leading to information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxUnder investigation
Red Hat Enterprise Linux 6webkitgtkOut of support scope
Red Hat Enterprise Linux 7firefoxUnder investigation
Red Hat Enterprise Linux 7webkitgtk3Not affected
Red Hat Enterprise Linux 7webkitgtk4Affected
Red Hat Enterprise Linux 8firefoxUnder investigation
Red Hat Enterprise Linux 8webkit2gtk3Affected
Red Hat Enterprise Linux 9firefoxUnder investigation
Red Hat Enterprise Linux 9webkit2gtk3FixedRHSA-2026:6909821.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2523904chromium-browser: skia: chromium-browser: skia: Information disclosure via uninitialized resource in Skia

EPSS

Процентиль: 25%
0.00347
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 6.5
nvd
около 1 месяца назад

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

msrc
29 дней назад

Chromium: CVE-2026-78914 Uninitialized resource in Skia

CVSS3: 6.5
debian
около 1 месяца назад

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 ...

CVSS3: 6.5
github
около 1 месяца назад

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

EPSS

Процентиль: 25%
0.00347
Низкий