Junglewise Threat Intelligence

CVE-2026-91746: Google Chrome integer overflow in Compositing

CVE-2026-91746 · Severity: medium · CVSS 4.3 · Published 2026-09-15

Executive brief

Google Chrome, the widely-used web browser, contains an integer overflow vulnerability in its compositing engine that could allow a remote attacker to access sensitive data from other websites. An attacker could trick a user into visiting a crafted webpage that exploits this flaw to read private information or session data from other origins, potentially compromising user privacy and account security.

Technical details

An integer overflow vulnerability exists in the Compositing component of Google Chrome prior to version 153.0.8010.47. The vulnerability is triggered when processing specially crafted HTML content, allowing a remote attacker to bypass same-origin policy restrictions and obtain cross-origin data. No authentication is required; the attack is delivered via a malicious webpage that the user must visit. The vulnerability enables information disclosure from other websites or applications the user is visiting in the same browser session. Google has patched this issue in Chrome 153.0.8010.47 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Chrome 153.0.8010.47

References

Related threats