Sceawere

Vulnerability Detail

CVE-2026-95283UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tint Buffer Overflow in Chrome

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
7h ago
Vendor
Google
Product
Chrome
Attack Type
Buffer overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-09-29T18:17:19.733Z",
  "pubdate": "2026-09-29T18:17:19.733Z",
  "executiveSummary": "This vulnerability is a buffer overflow condition identified within the Tint component of Google Chrome for Android, originating in the Chromium codebase.\nThe flaw allows a remote, unauthenticated attacker to trigger memory corruption, potentially leading to the execution of arbitrary code.\nA critical aspect of this vulnerability is the ability for an attacker to achieve code execution outside the confines of the Chrome sandbox, significantly elevating the risk profile.\nThe vulnerability is exploitable via a specially crafted HTML page, requiring only that a user navigates to the malicious content.\nGiven the high severity rating, this represents a significant threat to user data privacy and device integrity, as the sandbox escape could facilitate persistence or full system compromise.\nThe issue affects versions of Chrome for Android prior to 154.0.8037.57.",
  "technicalDetails": "The vulnerability resides within the Tint component, which is responsible for specific color or visual resource processing within the Chromium rendering engine.\nThe root cause is a buffer overflow, typically occurring when the application fails to perform adequate bounds checking while processing input from an untrusted source—in this case, a maliciously crafted HTML page.\nWhen the browser parses the crafted HTML, it triggers a memory operation that exceeds the allocated buffer capacity for the Tint component. This overwrites adjacent memory structures, which may include function pointers or return addresses on the heap or stack.\nAn attacker can leverage this memory corruption to redirect the control flow of the application to an arbitrary memory location, often pointing to shellcode or a ROP (Return-Oriented Programming) chain injected by the attacker.\nCrucially, the exploitation allows for a sandbox escape. Under normal operating conditions, the Chromium sandbox restricts the browser's ability to interact with the underlying Android operating system or access sensitive system APIs.\nBy bypassing these security boundaries, the attacker gains the ability to execute instructions with the privileges of the browser process, or potentially escalate privileges further depending on the underlying OS state.\nThe attack flow follows a predictable sequence: First, the attacker hosts or redirects a user to a malicious webpage containing the payload designed to overflow the Tint buffer. Second, the user visits the page via the vulnerable Chrome for Android browser. Third, the rendering process triggers the overflow upon processing the resource. Finally, the attacker achieves arbitrary code execution, escaping the sandbox to interact with the broader Android environment.\nBecause the payload is delivered via HTML, no user authentication or elevated privileges are required for the initial entry point, making this a high-risk remote code execution (RCE) vector."
}
CVE-2026-95283: Tint Buffer Overflow in Chrome (CRITICAL Severity, CVSS: 9.6) | Sceawere