OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-95362

HIGH · CVSS 8.8 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A cross-site request forgery vulnerability in the DevTools of Google Chrome prior to version 154.0.8037.57 allows remote attackers to exploit web origin policy through social engineering techniques via a specially crafted HTML page. This could lead to unauthorized actions being performed on behalf of users without their consent. Organizations using affected versions of Chrome should prioritize updates to mitigate potential security risks.

CVE
CVE-2026-95362
Severity
HIGH
CVSS
8.8
EPSS
0.21%
Chrome

Original NVD Description

Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)