Description
Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Score: 3.4 Low
EPSS: n/a
KEV: No
Impact: Remote Memory Disclosure
Action: Patch
AI Analysis

Impact

An uninitialized resource in Chrome’s Media component on Windows allows a remote attacker who has already compromised the renderer process to read memory outside the sandbox through a crafted HTML page. This flaw is identified as CWE‑908 (Uninitialized Resource Used) and could expose sensitive data from the renderer, leading to information disclosure. The vulnerability is not a direct code execution flaw but enables a low‑barrier path to leak memory content.

Affected Systems

The issue affects Google Chrome running on Windows that are older than version 154.0.8037.92, which is the release that contains the remediation. Users of the stable channel are at risk if they have not installed the update provided in the September 2026 release notes.

Risk and Exploitability

The CVSS score of 3.4 classifies the risk as low, however Chromium’s internal severity rating is high due to the potential for memory exposure. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The attack requires an attacker to already have access to the renderer process or to deceive a user into loading a malicious page that interacts with the vulnerable media handler. While the exploitation path is not trivial, the combination of a compromised renderer and crafted HTML provides a realistic condition for memory disclosure.

Generated by OpenCVE AI on September 30, 2026 at 10:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 154.0.8037.92 or newer to patch the uninitialized media resource flaw
  • If an upgrade is temporarily infeasible, consider disabling hardware acceleration or media feature flags via chrome://flags or an enterprise policy until the update can be applied
  • Configure Chrome to restrict rendering of third‑party media content to known safe origins using enterprise policy settings (e.g., block untrusted media origins)

Generated by OpenCVE AI on September 30, 2026 at 10:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Remote Memory Disclosure via Uninitialized Media Resource in Chrome on Windows

Tue, 29 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T21:06:31.197Z

Reserved: 2026-09-28T21:44:30.227Z

Link: CVE-2026-102315

cve-icon Vulnrichment

Updated: 2026-09-29T21:06:28.276Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T20:17:14.663

Modified: 2026-09-29T22:17:07.187

Link: CVE-2026-102315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T11:00:17Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource