Junglewise Threat Intelligence

CVE-2026-91730: Google Chrome incomplete cleanup in GetUserMedia

CVE-2026-91730 · Severity: low · CVSS 3.1 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's GetUserMedia feature had incomplete cleanup logic that could allow an attacker to access cross-origin data. An attacker who already compromised the browser rendering engine and used social engineering to trick a user could exploit this to steal sensitive information from other websites the user visits.

Technical details

This vulnerability stems from incomplete cleanup in Chrome's GetUserMedia implementation, a feature that manages access to webcams, microphones, and other media devices. The vulnerability requires two preconditions: the attacker must first compromise the renderer process (the sandboxed process that executes web content) and then use social engineering to manipulate the user into visiting a crafted HTML page. Once exploited, the attacker can read cross-origin data from other websites. The issue was resolved in Chrome version 153.0.8010.47.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Chrome 153.0.8010.47

References

Related threats