CVE-2026-95366
Description
AI Translation Available
Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
672
Operation on a Resource after Expiration or Release
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Other
Availability
Potential Impacts:
Modify Application Data
Read Application Data
Other
Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies:
Mobile
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop…
https://issues.chromium.org/issues/497204165