SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90890

MEDIUM · CVSS 5.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The ASRock Polychrome SYNC/RGB software utility for Chrome contains an untrusted pointer dereference vulnerability that allows authenticated local attackers to exploit the driver by sending specially crafted IOCTL requests. This can lead to an operating system crash, potentially disrupting system availability. Organizations using this software should prioritize patching to mitigate the risk of local exploitation.

CVE
CVE-2026-90890
Severity
MEDIUM
CVSS
5.5
EPSS
N/A
Chrome

Original NVD Description

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.