Description
Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Cross-origin data leakage
Action: Immediate patch
AI Analysis

Impact

An integer overflow occurs in the Skia graphics library used by Google Chrome, allowing a remote attacker to use a specially crafted HTML page to read data from other origins. This flaw results in a confidentiality breach where sensitive data can be exposed to the attacker. The weakness is an instance of integer overflow (CWE‑190).

Affected Systems

Google Chrome versions earlier than 154.0.8037.97 across all platforms are affected. The vulnerability was discovered in the Skia library used by the browser.

Risk and Exploitability

The bug is rated high severity with no EPSS score available, and it is not currently listed in the CISA KEV catalog. The exploit requires the victim to open a carefully crafted web page, after which the overflow can be triggered in memory. Because the attack occurs in the rendering engine, a remote attacker can obtain cross-origin data from any site the victim visits while the browser is running. No additional prerequisites were identified beyond user interaction with the malicious page.

Generated by OpenCVE AI on October 2, 2026 at 17:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to Chrome 154.0.8037.97 or later
  • Ensure Chrome is set to use the sandbox and secure settings
  • Avoid loading untrusted HTML content while the vulnerability is unresolved

Generated by OpenCVE AI on October 2, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Title Integer overflow in Skia causes cross‑origin data leakage via crafted HTML pages

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-190
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-02T16:07:55.593Z

Reserved: 2026-09-30T23:12:21.560Z

Link: CVE-2026-103629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:44.043

Modified: 2026-10-02T17:47:56.067

Link: CVE-2026-103629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:30:18Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound