CVE-2026-95376
HIGHCVSS 8/10
Last modified
CVE-2026-95376 is a high-severity vulnerability rated 8/10 on the CVSS scale. Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium).
Description
Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | < 154.0.8037.57 |
References
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.htmlRelease Notes, Vendor Advisory
- https://issues.chromium.org/issues/513134076Exploit, Issue Tracking, Mitigation
- https://issues.chromium.org/issues/513134076Exploit, Issue Tracking, Mitigation
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-95376?
Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
How severe is CVE-2026-95376?
CVE-2026-95376 has a CVSS score of 8/10 (HIGH severity).
How do I fix CVE-2026-95376?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-95370Inappropriate implementation in NFC in Google Chrome prior t…5.4
- CVE-2026-95371Missing authorization in Views in Google Chrome on on Mac pr…5.4
- CVE-2026-95372Use after free in Chromecast in Google Chrome prior to 154.0…8.3
- CVE-2026-95373Use after free in DevTools in Google Chrome prior to 154.0.8…8.8
- CVE-2026-95374Incorrect authorization in Network in Google Chrome prior to…6.5
- CVE-2026-95375Incorrect authorization in BrowserTag in Google Chrome prior…6.3
- CVE-2026-9538Archive::Tar versions before 3.10 for Perl allow memory exha…7.5
- CVE-2026-95380Type confusion in V8 in Google Chrome prior to 154.0.8037.57…8.8
- CVE-2026-95381Improper input validation in Printing in Google Chrome prior…8.3
- CVE-2026-95382Improper input validation in Auth in Google Chrome prior to …6.5
- CVE-2026-95384Race condition in Transactions Platform in Google Chrome pri…5.3
- CVE-2026-95385Inappropriate implementation in PlatformIntegration in Googl…6.5
Are you affected by CVE-2026-95376?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
