CVE-2026-91708: Race Condition
Published Sep 15, 2026
·Updated
Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<153.0.8010.47
Event History
Sep 15, 2026
CVE Published
via MITRE·08:41 PM
Data Sourced
via MITRE·08:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What must an attacker achieve before exploiting this issue?
The attacker must first compromise the Chrome renderer process. The issue is then exploitable remotely through a crafted HTML page.
2
What is the potential impact after successful exploitation?
A successful attacker could obtain cross-origin data.
3
Which Chrome versions are affected?
Google Chrome versions prior to 153.0.8010.47 are affected.