Description
Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: Memory disclosure via out‑of‑bounds read in WebGL
Action: Patch Now
AI Analysis

Impact

An out‑of‑bounds read in the WebGL engine allows a remote attacker to read memory contents outside the sandbox by loading a specially crafted HTML page. The flaw is a classic out‑of‑bounds read, identified as CWE‑125, and could expose sensitive data stored in the browser’s memory. The Chromium project rates the severity of this issue as high.

Affected Systems

Google Chrome desktop browsers on the stable channel before version 154.0.8037.92 are affected.

Risk and Exploitability

The CVSS score is 4.7, indicating a moderate overall severity. No EPSS data is currently available and the vulnerability has not been listed in the CISA KEV catalog. Exploitation requires a user to visit a malicious or compromised web page that serves the crafted content, so the attack vector is remote but user‑initiated.

Generated by OpenCVE AI on September 30, 2026 at 08:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 154.0.8037.92 or later
  • Enable automatic updates to ensure timely reception of security patches
  • If an immediate upgrade is not possible, disable WebGL in the browser settings to block the vulnerable code path

Generated by OpenCVE AI on September 30, 2026 at 08:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Out of bounds read in WebGL
References
Metrics threat_severity

None

threat_severity

Important


Tue, 29 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T21:08:45.436Z

Reserved: 2026-09-28T21:44:40.695Z

Link: CVE-2026-102318

cve-icon Vulnrichment

Updated: 2026-09-29T21:08:40.001Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T20:17:15.077

Modified: 2026-09-29T22:17:07.370

Link: CVE-2026-102318

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-29T19:45:05Z

Links: CVE-2026-102318 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T09:00:07Z

Weaknesses