CVE-2026-102303: Medium severity Google Chrome for Android vulnerability
Published Sep 29, 2026
·Updated
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome for Android<154.0.8037.92
Event History
Sep 29, 2026
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Google Chrome for Android versions prior to 154.0.8037.92 are affected. The provided information does not identify any affected desktop Chrome versions.
2
What must an attacker do to exploit this issue?
The attacker needs to cause a user to load a crafted HTML page remotely. Successful exploitation can allow the attacker to obtain cross-origin data.
3
Is user interaction required?
A user must reach or load the attacker-crafted HTML page. No additional interaction requirements are stated in the provided information.
4
How can I determine whether a device is vulnerable?
Check the installed Google Chrome for Android version. Versions earlier than 154.0.8037.92 are affected.