Information Leak in Google Chrome Affects User Privacy and Security
CVE-2026-95367

5.3MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-95367?

A vulnerability exists in Google Chrome that enables an attacker to exploit an information leak through the DataTransfer functionality. Prior to version 154.0.8037.57, this flaw could allow a remote attacker, who had already compromised the renderer process, to utilize social engineering techniques to retrieve sensitive information by employing a specially crafted HTML page. This breach highlights essential concerns regarding user privacy and the security of personal data.

Affected Version(s)

Chrome 154.0.8037.57

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.