Skip to content
GoogleCVE-2026-95376

Externally controlled reference in DevTools in Google Chrome prior to...

High8.0CVE-2026-95376 · Published Sep 29, 2026 · updated Oct 1, 2026

Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 154.0.8037.57, < 154.0.8037.57154.0.8037.57
Details and references

More Google advisories

All Google
Advisory
Google Chrome: improper authorization
High7.5Sep 29
Google Chrome: type confusion
High8.8Sep 29
Google Chrome: cross-site scripting
Medium6.1Sep 29
Google Chrome: improper authorization
Medium6.5Sep 29
Google Chrome: buffer overflow
Critical9.6Sep 29
Google Chrome: out-of-bounds read
Medium4.7Sep 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.