Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-78984

CVE-2026-78984: Google Chrome GPU Information Disclosure

CVE-2026-78984 is an information disclosure flaw in Google Chrome GPU allowing attackers to read memory outside the sandbox. This post explains the technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2026-78984 Overview

CVE-2026-78984 is an uninitialized resource vulnerability [CWE-908] in the GPU component of Google Chrome. The flaw affects Chrome versions prior to 152.0.7977.65. A remote attacker who has already compromised the renderer process can leverage a crafted HTML page to read memory outside the browser sandbox. Google classifies the Chromium security severity as Medium.

Exploitation requires a preexisting renderer compromise, so this issue is typically chained with a separate renderer exploit. Successful exploitation exposes memory from the more privileged GPU process, weakening Chrome's sandbox boundary.

Critical Impact

Attackers chaining a renderer compromise with CVE-2026-78984 can read memory outside the sandbox, potentially leaking sensitive data from the GPU process.

Affected Products

  • Google Chrome versions prior to 152.0.7977.65 (Desktop Stable channel)
  • Chromium-based browsers incorporating vulnerable GPU code paths
  • Downstream distributions that have not merged the upstream fix

Discovery Timeline

  • 2026-08-25 - CVE-2026-78984 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-78984

Vulnerability Analysis

The vulnerability originates in Chrome's GPU process, which handles graphics operations on behalf of renderer processes. An uninitialized resource is allocated and then made accessible before its contents are fully populated with intended values. The residual memory contents can include data from prior allocations within the GPU process address space.

Because the GPU process runs at a higher privilege level than the sandboxed renderer, reading its memory constitutes a sandbox escape primitive. The attack does not directly achieve code execution but provides an information leak that supports further exploitation, such as bypassing address space layout randomization (ASLR) in follow-on stages.

Root Cause

The root cause is a Use of Uninitialized Resource condition [CWE-908] in GPU code. Memory or resource state that should be zeroed or explicitly initialized before being exposed across the renderer-to-GPU interprocess boundary is instead returned in an indeterminate state. Details are tracked in Chromium Issue #535374213.

Attack Vector

Exploitation requires two conditions. First, the attacker must already control a compromised renderer process, typically through a separate renderer-side vulnerability. Second, the attacker delivers a crafted HTML page that issues GPU commands designed to trigger the uninitialized read path.

The crafted content causes the GPU process to return uninitialized data to the renderer, which the attacker then exfiltrates. No user interaction beyond visiting the malicious page is required once the renderer is compromised. See the Google Chrome Stable Update advisory for vendor guidance.

Detection Methods for CVE-2026-78984

Indicators of Compromise

  • Chrome installations reporting a version string earlier than 152.0.7977.65 on endpoints that browse untrusted content.
  • Anomalous child GPU process behavior, including unexpected memory read patterns or crashes originating from graphics command buffers.
  • Renderer processes issuing sequences of GPU commands that correlate with public proof-of-concept patterns once released.

Detection Strategies

  • Inventory Chrome and Chromium-derivative versions across managed endpoints and flag installs below 152.0.7977.65.
  • Monitor for renderer process compromise indicators, since this vulnerability requires a prior renderer exploit to be useful.
  • Correlate GPU process crashes or memory access anomalies with recent renderer activity from untrusted origins.

Monitoring Recommendations

  • Ingest browser telemetry and endpoint process events into a centralized data lake for cross-process correlation.
  • Track outbound web traffic patterns from browser processes for signs of data exfiltration following renderer exploitation.
  • Alert on Chrome auto-update failures that leave endpoints stuck on vulnerable builds.

How to Mitigate CVE-2026-78984

Immediate Actions Required

  • Update Google Chrome to version 152.0.7977.65 or later on all managed endpoints.
  • Verify Chrome auto-update is enabled and functioning on both user and server workstations.
  • Restart Chrome after patch deployment, since updates only take effect on browser restart.
  • Audit Chromium-based browsers (Edge, Brave, Opera, Vivaldi) for upstream patch adoption.

Patch Information

Google addressed CVE-2026-78984 in the Chrome Stable channel with build 152.0.7977.65. Refer to the Chrome Releases blog post for the official announcement. Chromium-based browsers should adopt the corresponding upstream fix tracked in Chromium Issue #535374213.

Workarounds

  • Restrict browsing on high-risk endpoints to trusted sites until patching completes, reducing the likelihood of a renderer compromise.
  • Enforce Site Isolation and strict security policies via enterprise browser policies to raise the cost of renderer exploitation.
  • Deploy content filtering and DNS-layer controls to block delivery of exploit-hosting pages.
bash
# Verify Chrome version on Linux/macOS endpoints
google-chrome --version

# Windows PowerShell version check
(Get-Item "$env:ProgramFiles\Google\Chrome\Application\chrome.exe").VersionInfo.ProductVersion

# Enforce minimum version via enterprise policy (example JSON)
# Chrome Enterprise policy file: policies.json
{
  "BrowserSwitcherEnabled": false,
  "ComponentUpdatesEnabled": true,
  "DefaultBrowserSettingEnabled": true
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.