CVE-2026-76042: Use of uninitialized resource in GPU
Chromium: CVE-2026-76042 Use of uninitialized resource in GPU
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.101 - Upgrade
Upgrade
Google Chrome (Chromium-based)to a version that resolves this vulnerability.Fixed in 151.0.7922.169
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What access does an attacker need before exploiting this issue?
Exploitation requires the attacker to have already compromised the Chrome renderer process. The vulnerability can then be triggered with a crafted HTML page to read memory outside the sandbox.
Which Chrome versions are affected, and is a mitigation available if patching is delayed?
Google Chrome versions prior to 151.0.7922.169 are affected. The provided information does not identify any configuration prerequisite or workaround for systems that cannot be updated immediately.