CVE-2026-95376
Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
- Published Sep 29, 2026
- CVSS 8.0 high
- 0.2% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
- A fix is available