CVE-2026-95376: Google Chrome

High severity, CVSS 8.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

Affected products

  • Google Chrome: before 154.0.8037.57 (fixed in 154.0.8037.57)

Published 2026-09-29. Last modified 2026-10-01.