SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91733

HIGH · CVSS 8.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the Skia graphics library of Google Chrome prior to version 153.0.8010.47 allows remote attackers to exploit improper state validation, potentially enabling them to read memory outside the sandbox through a specially crafted HTML page. This poses a significant risk to users, particularly those in environments where web content is rendered, as it could lead to unauthorized data access. Organizations using affected versions of Chrome should prioritize updates to mitigate this security risk.

CVE
CVE-2026-91733
Severity
HIGH
CVSS
8.3
EPSS
0.29%
Chrome

Original NVD Description

Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)