Junglewise Threat Intelligence

CVE-2026-87592: Google Chrome out of bounds read in Tint

CVE-2026-87592 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an out of bounds memory read vulnerability in the Tint graphics component. A remote attacker can exploit this by serving a specially crafted HTML page, potentially allowing them to read sensitive data from Chrome's memory sandbox. This could lead to exposure of user data or information about the browser's internal state.

Technical details

This is an out of bounds read vulnerability in the Tint graphics library component within Google Chrome prior to version 153.0.8010.36. The vulnerability is triggered via a crafted HTML page and allows a remote attacker to read memory beyond the allocated bounds of a buffer within the Chrome sandbox environment. No authentication or user interaction is required beyond viewing the malicious web page. The attack vector is network-based, exploitable remotely. The fix is available in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87592 publicly disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released with fix

References

Related threats