
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-91746 is an integer overflow vulnerability in the Compositing component of Google Chrome that allows a remote attacker to obtain cross-origin data via a crafted HTML page. It affects all versions of Google Chrome prior to 153.0.8010.47 and was reported to Google on September 2, 2026, with a patch released on September 15, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), though Google rates its internal severity as High (Chrome Release, GitHub Advisory).
The root cause is an integer overflow or wraparound (CWE-190) in Chrome's Compositing subsystem, which handles the rendering and layering of web content. When processing a specially crafted HTML page, an arithmetic operation on an integer value exceeds the bounds of its storage type, causing it to wrap around to an unexpected value. This corrupted value can then be used to read memory or data belonging to a different origin, effectively bypassing the browser's same-origin policy. The bug was tracked internally as Chromium issue 556260782 and was discovered and reported by Google's own security team (Chrome Release, GitHub Advisory).
Successful exploitation results in unauthorized disclosure of cross-origin data, meaning an attacker-controlled web page could read sensitive information from another origin that the browser's same-origin policy is designed to protect. The confidentiality impact is rated as low (partial data exposure), with no integrity or availability impact. While this vulnerability does not enable remote code execution on its own, cross-origin data leakage can expose session tokens, credentials, or other sensitive content rendered in the browser, potentially enabling further attacks (GitHub Advisory, Chrome Release).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The vulnerability requires user interaction — specifically, a victim must visit a malicious HTML page — which reduces the likelihood of mass exploitation. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (GitHub Advisory).
Google has released a fix in Chrome 153.0.8010.47 (Linux) and 153.0.8010.47/.48 (Windows and Mac), which began rolling out on September 15, 2026. Users should update Google Chrome to version 153.0.8010.47 or later immediately, and organizations should enable automatic updates to ensure timely patching. No configuration-based workaround is available; upgrading is the only effective remediation (Chrome Release).
The Chrome 153 update, which includes 42 security fixes (3 Critical, numerous High), received coverage from cybersecurity news outlets including CyberSecurityNews, GBHackers, Cryptika, and CyberPress, generally highlighting the breadth of the release rather than focusing specifically on CVE-2026-91746. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard vulnerability aggregator coverage (Chrome Release).
Fix availability across major Linux distributions and their releases.
bookworm
chromium: 153.0.8010.47-1
sid
chromium: 153.0.8010.47-1
trixie
chromium: 153.0.8010.47-2~deb13u1
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."