Description
Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-15
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A flaw in the cleanup logic of GetUserMedia in Google Chrome, prior to version 153.0.8010.47, permits a remote attacker who has already compromised a renderer process to obtain cross‑origin data. The vulnerability stems from incomplete resource handling, which allows the attacker to read data that should remain inaccessible. According to the report, the flaw is classified as Chromium security severity Medium, indicating that the failure could reveal confidential data but does not enable direct code execution or denial of service.

Affected Systems

The affected product is Google Chrome. The vulnerability exists in all Chrome builds prior to version 153.0.8010.47; the exact revision is not listed. Users running older stable channel releases before the 2026 September update are at risk.

Risk and Exploitability

The CVSS score of 3.1 signals a low‑to‑moderate severity. The EPSS score is below 1%, indicating a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog, further implying that widespread exploitation has not been observed. The attack flow requires an attacker to first compromise a renderer process and then leverage social engineering to serve a crafted HTML page that abuses the GetUserMedia API, suggesting that defense in depth is necessary to mitigate possible exploitation.

Generated by OpenCVE AI on September 16, 2026 at 20:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.47 or newer to contain the GetUserMedia cleanup fix.
  • Configure Chrome to enforce the Same‑Origin Policy for media APIs, for example by using site‑wide Content Security Policy directives that restrict media permissions.
  • Educate users to avoid clicking on suspicious links that could trigger social‑engineering based media requests, and consider disabling the GetUserMedia functionality on sites where it is not required.

Generated by OpenCVE AI on September 16, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Disclosure via GetUserMedia in Chrome

Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-459
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-16T10:11:47.052Z

Reserved: 2026-09-14T22:52:20.778Z

Link: CVE-2026-91730

cve-icon Vulnrichment

Updated: 2026-09-16T10:11:39.864Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:46.393

Modified: 2026-09-16T19:15:47.623

Link: CVE-2026-91730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:45:05Z

Weaknesses