OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-95344

HIGH · CVSS 8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A race condition in the DevTools component of Google Chrome prior to version 154.0.8037.57 allows remote attackers to exploit a crafted Chrome extension, potentially bypassing site isolation protections through social engineering tactics. This vulnerability poses a medium security risk, particularly for users and organizations that rely on Chrome for web applications and sensitive data transactions. It is essential for all Chrome users, especially those in security-sensitive environments, to prioritize updates to mitigate this risk.

CVE
CVE-2026-95344
Severity
HIGH
CVSS
8
EPSS
0.23%
Chrome

Original NVD Description

Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome extension. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)