SEPTEMBER 30, 2026
Live Feed
Back to database
Case File

CVE-2026-102315

LOW · CVSS 3.4

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-09-30

CyberRota Analysis

AI-Generated

An uninitialized resource vulnerability in the Media component of Google Chrome on Windows allows remote attackers to read memory outside the sandbox by exploiting a compromised renderer process through a specially crafted HTML page. While the CVSS score is low, the potential for sensitive data exposure should prompt organizations using affected versions of Chrome to prioritize updates. Users and administrators of Windows systems running Chrome should ensure they are on version 154.0.8037.92 or later to mitigate this risk.

CVE
CVE-2026-102315
Severity
LOW
CVSS
3.4
EPSS
N/A
Windows Chrome

Original NVD Description

Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)