Authorization Flaw in PictureInPicture Feature of Google Chrome
CVE-2026-95340

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-95340?

A security issue in the PictureInPicture functionality of Google Chrome prior to version 154.0.8037.57 can be exploited by remote attackers. By utilizing social engineering techniques, these attackers can craft malicious HTML pages that enable them to circumvent web origin policies. This vulnerability underscores the importance of user awareness regarding potential manipulation when interacting with web content.

Affected Version(s)

Chrome 154.0.8037.57

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.