Junglewise Threat Intelligence

CVE-2026-91731: Google Chrome type confusion in Compositing

CVE-2026-91731 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's rendering engine contains a type confusion vulnerability in its Compositing component that allows attackers to execute arbitrary code within the browser's sandbox by delivering a specially crafted web page. An attacker could compromise a user's browser session and potentially access sensitive data or execute malicious actions on visited websites.

Technical details

A type confusion vulnerability exists in the Compositing component of Google Chrome's rendering engine (Blink). The vulnerability allows a remote attacker to cause incorrect type interpretation, leading to out-of-bounds memory access or use-after-free conditions. The attack requires no authentication and is triggered via a crafted HTML page delivered over the network, requiring only user interaction (visiting a malicious website). Successful exploitation results in code execution within the Chrome sandbox environment. The vulnerability affects Chrome versions prior to 153.0.8010.47, which includes the fix.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed

References

Related threats