Disclosure summary
Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Source-reported weakness categories
CWE-610
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-95376
Open original source · Updated Oct 01, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| chrome | * {"versionEndExcluding":"154.0.8037.57"} |
MSRC Security Update Guide · RSS-b7b4ee5e64d6a583bdc4ae0a9bef9449ea4
Open original source · Updated Sep 25, 2026
Chromium CVE-2026-95376: Externally controlled reference in DevTools
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- chromereleases.googleblog.com — Release Notes, Vendor Advisory
- issues.chromium.org — Exploit, Issue Tracking, Mitigation
- issues.chromium.org — Exploit, Issue Tracking, Mitigation
PUBLISHED 2026-09-29T14:17:31-04:00
MODIFIED 2026-10-01T10:05:52-04:00
INGESTED 2026-10-06T11:43:05-04:00