CVE-2026-76042: Google Chrome vulnerability
Published Aug 18, 2026
·Updated
Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<151.0.7922.169
Event History
Aug 18, 2026
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need before exploiting this issue?
Exploitation requires the attacker to have already compromised the Chrome renderer process. The vulnerability can then be triggered with a crafted HTML page to read memory outside the sandbox.
2
Which Chrome versions are affected, and is a mitigation available if patching is delayed?
Google Chrome versions prior to 151.0.7922.169 are affected. The provided information does not identify any configuration prerequisite or workaround for systems that cannot be updated immediately.