Description
Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote information disclosure via cross‑origin data leak
Action: Immediate Patch
AI Analysis

Impact

An integer overflow in Chrome’s compositing engine allows a crafted web page to read memory that contains data from a different origin, violating the same‑origin policy and exposing confidential information to an attacker. This flaw can be exploited from the network without any local privileges and results in confidentiality compromise of content that should remain isolated.

Affected Systems

Google Chrome versions earlier than 154.0.8037.97 are affected. Users running these releases are susceptible to the described data‑leak flaw.

Risk and Exploitability

Chromium labels the issue as high severity; while no EPSS score is available, the vulnerability can be triggered by any web page that an end‑user visits, making exploitation highly feasible. The flaw is not listed in the CISA KEV catalog, but the lack of an exploitation probability metric does not reduce the urgency of applying a fix.

Generated by OpenCVE AI on October 2, 2026 at 17:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to 154.0.8037.97 or later (or apply any later patch that contains the compositing fix).
  • If a patch cannot be applied immediately, disable hardware acceleration or compositing features via Chrome settings to mitigate the integer‑overflow trigger.
  • Deploy Chrome update policies across the organization to ensure all clients receive the remediation at the earliest opportunity.

Generated by OpenCVE AI on October 2, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Compositing Leaks Cross-Origin Data

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-190
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-02T16:07:54.589Z

Reserved: 2026-09-30T23:12:12.746Z

Link: CVE-2026-103621

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:43.180

Modified: 2026-10-02T17:47:56.067

Link: CVE-2026-103621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:30:18Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound