SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-16422

HIGH · CVSS 7.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Google Chrome on Linux versions prior to 150.0.7871.182 is vulnerable due to insufficient validation of untrusted input in its certificate handling. This flaw allows attackers in a privileged network position to execute domain spoofing through malicious network traffic, potentially leading to unauthorized access or data interception. Organizations using affected versions of Chrome on Linux should prioritize patching to mitigate this high-severity risk.

CVE
CVE-2026-16422
Severity
HIGH
CVSS
7.5
EPSS
0.15%
Linux Chrome

Original NVD Description

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)