CVE-2026-79020

Google · Chrome

An out of bounds read vulnerability exists in the Skia graphics library within Google Chrome, allowing a remote attacker to potentially read memory via a crafted media file.

Executive summary

A memory corruption vulnerability in Google Chrome allows remote attackers to potentially access sensitive data via malicious media files.

Vulnerability

This is an out of bounds read vulnerability (CWE-125) located within the Skia component. The attack is unauthenticated and requires user interaction, as it is triggered when a user processes a specially crafted media file.

Business impact

Successful exploitation of this vulnerability could allow an attacker to read memory contents within the browser sandbox, potentially exposing sensitive information or facilitating further exploitation. While the Chromium project classifies this as medium severity, the CVSS score of 8.1 reflects a high risk due to the potential for significant information disclosure and impacts on system availability.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later to incorporate the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual browser crashes or unexpected memory access patterns that may indicate attempts to trigger this flaw.

Compensating Controls: Ensure that browser security features, such as site isolation and sandboxing, are enabled and enforced via group policy or configuration management.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for unauthorized memory access, organizations should prioritize updating all instances of Google Chrome to the latest stable version. This vulnerability highlights the importance of keeping browser software current to protect against memory-based attacks that bypass standard security boundaries.

More Google CVEs

Sources