Junglewise Threat Intelligence

CVE-2026-91714: Google Chrome observable discrepancy in font handling

CVE-2026-91714 · Severity: medium · CVSS 5.3 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome versions prior to 153.0.8010.47 contain a vulnerability in how fonts are rendered that allows an attacker to expose sensitive information through a specially crafted web page combined with social engineering. An attacker could trick a user into visiting a malicious website to leak data such as passwords or personal information that should remain hidden.

Technical details

An observable discrepancy vulnerability in the font rendering subsystem of Google Chrome allows information disclosure via a specially crafted HTML page. The vulnerability requires user interaction—specifically, social engineering to trick the user into visiting a malicious website. The flaw enables a remote, network-based attacker to leak sensitive information from the browser through observable timing or behavioral differences in font handling. The vulnerability affects Chrome versions before 153.0.8010.47 and has been patched in that release.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Chrome 153.0.8010.47

References

Related threats