CVE-2026-102313: Medium severity Google Chrome vulnerability
Published Sep 29, 2026
·Updated
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<154.0.8037.92
Event History
Sep 29, 2026
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are identified as affected?
The affected deployments are Google Chrome installations on Windows with versions earlier than 154.0.8037.92. The provided information does not identify other operating systems as affected.
2
What must an attacker do to trigger the issue?
The issue can be triggered by a remote attacker using a crafted HTML page. No additional attacker privileges or local access requirements are stated.
3
How can administrators determine whether a system needs remediation?
Check the installed Google Chrome version on Windows. Systems running a version earlier than 154.0.8037.92 are within the stated affected range.