CVE-2026-91733
Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-754
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2025-11925 — Incorrect Content-Type Header
- CVE-2026-79073 — Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exe
- CVE-2026-30960 — RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
- CVE-2025-0129 — Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser
- CVE-2026-79072 — Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall
- CVE-2026-24054 — Kata Containers Runtime: Host block device can be hotplugged to the VM if the container image is malformed or contains no layers
- CVE-2026-21693 — iccDEV has Type Confusion in CIccSegmentedCurveXml::ToXml() at IccXML/IccLibXML/IccMpeXml.cpp
- CVE-2025-24303 — Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethern