Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-91746
vulnerability analysis and mitigation

Overview

CVE-2026-91746 is an integer overflow vulnerability in the Compositing component of Google Chrome that allows a remote attacker to obtain cross-origin data via a crafted HTML page. It affects all versions of Google Chrome prior to 153.0.8010.47 and was reported to Google on September 2, 2026, with a patch released on September 15, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), though Google rates its internal severity as High (Chrome Release, GitHub Advisory).

Technical details

The root cause is an integer overflow or wraparound (CWE-190) in Chrome's Compositing subsystem, which handles the rendering and layering of web content. When processing a specially crafted HTML page, an arithmetic operation on an integer value exceeds the bounds of its storage type, causing it to wrap around to an unexpected value. This corrupted value can then be used to read memory or data belonging to a different origin, effectively bypassing the browser's same-origin policy. The bug was tracked internally as Chromium issue 556260782 and was discovered and reported by Google's own security team (Chrome Release, GitHub Advisory).

Impact

Successful exploitation results in unauthorized disclosure of cross-origin data, meaning an attacker-controlled web page could read sensitive information from another origin that the browser's same-origin policy is designed to protect. The confidentiality impact is rated as low (partial data exposure), with no integrity or availability impact. While this vulnerability does not enable remote code execution on its own, cross-origin data leakage can expose session tokens, credentials, or other sensitive content rendered in the browser, potentially enabling further attacks (GitHub Advisory, Chrome Release).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The vulnerability requires user interaction — specifically, a victim must visit a malicious HTML page — which reduces the likelihood of mass exploitation. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (GitHub Advisory).

Exploitation steps

  1. Craft malicious HTML page: An attacker creates a web page containing HTML/JavaScript that triggers the integer overflow in Chrome's Compositing component, likely by constructing layered or composited elements with dimensions or counts that cause an arithmetic wraparound.
  2. Host the page: The attacker hosts the crafted page on an attacker-controlled server accessible over the internet.
  3. Lure the victim: The attacker delivers a link to the malicious page via phishing email, social media, or malicious advertisement, inducing the target to open it in a vulnerable version of Chrome (prior to 153.0.8010.47).
  4. Trigger the overflow: When the victim's browser renders the page, the integer overflow occurs in the Compositing subsystem, causing a miscalculation that allows the attacker's page to read memory or data from a cross-origin context.
  5. Exfiltrate cross-origin data: The attacker's JavaScript collects the leaked cross-origin data (e.g., content from another tab or iframe belonging to a different origin) and transmits it to an attacker-controlled server (Chrome Release, GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the browser to unexpected external domains shortly after visiting an unfamiliar web page; unusual data exfiltration patterns (e.g., encoded query parameters or POST bodies) to attacker-controlled infrastructure.
  • Logs: Browser history or proxy logs showing visits to suspicious or newly registered domains serving complex HTML/JavaScript content with heavily layered compositing elements.
  • Process: Chrome renderer processes exhibiting anomalous memory access patterns or crashes (e.g., crash dumps referencing Compositing or rendering pipeline components) on versions prior to 153.0.8010.47.

Mitigation and workarounds

Google has released a fix in Chrome 153.0.8010.47 (Linux) and 153.0.8010.47/.48 (Windows and Mac), which began rolling out on September 15, 2026. Users should update Google Chrome to version 153.0.8010.47 or later immediately, and organizations should enable automatic updates to ensure timely patching. No configuration-based workaround is available; upgrading is the only effective remediation (Chrome Release).

Community reactions

The Chrome 153 update, which includes 42 security fixes (3 Critical, numerous High), received coverage from cybersecurity news outlets including CyberSecurityNews, GBHackers, Cryptika, and CyberPress, generally highlighting the breadth of the release rather than focusing specifically on CVE-2026-91746. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard vulnerability aggregator coverage (Chrome Release).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 153.0.8010.47-1

Fixed

sid

chromium: 153.0.8010.47-1

Fixed

trixie

chromium: 153.0.8010.47-2~deb13u1

Fixed

Ubuntu

Unknown

devel

chromium-browser

Not Affected

jammy

chromium-browser

Not Affected

noble

chromium-browser

Not Affected

noble (esm-apps)

chromium-browser

Not Affected

resolute

chromium-browser

Not Affected

resolute (esm-apps)

chromium-browser

Not Affected

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management