Junglewise Threat Intelligence

CVE-2026-91725: Google Chrome observable discrepancy in CSS information leak

CVE-2026-91725 · Severity: medium · CVSS 5.3 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a vulnerability in how it handles CSS that allows attackers to infer sensitive information by observing subtle visual or behavioral differences in web pages. An attacker can craft a malicious HTML page that, when visited by a user, reveals private data through CSS-based side-channel attacks, potentially exposing browsing history, cached content, or other sensitive state.

Technical details

This vulnerability is classified as an observable discrepancy in CSS handling, representing a side-channel information leak. The root cause lies in Chrome's CSS rendering engine failing to properly isolate or obfuscate the timing or visual output of CSS operations when processing crafted HTML. The attack vector is network-based and requires only that a user visit a malicious web page; no authentication or special privileges are needed. An attacker can exploit this to leak sensitive information through CSS selector timing, computed style observations, or rendering behavior differences. The vulnerability was fixed in Chrome version 153.0.8010.47 and later releases.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in version 153.0.8010.47

References

Related threats