Authorization Flaw in Google Chrome Allows Potential Cross-Origin Data Exposure
CVE-2026-95368

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-95368?

A vulnerability in Google Chrome allows remote attackers to exploit an incorrect authorization issue in DevTools, potentially leading to unauthorized access of cross-origin data. This exploit can be executed through a crafted HTML page, which may rely on social engineering tactics to trick users into interaction. Affected users should consider updating their browser to the latest version to mitigate this issue.

Affected Version(s)

Chrome 154.0.8037.57

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.