CVE-2026-95274

unknown
Assigned by CNA: chrome
Published 2026-09-29 · Modified 2026-09-29
CVSS v3
—
CVSS v4 NEW
—
not yet in upstream
VIR risk
—

Description

Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Predictions

Exploit likelihood
20%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-95274 NameCVE-2026-95274 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus chromium (PTS)bookworm150.0.7871.100-1~deb12u1vulnerable bookworm…

CVE-2026-95274

NameCVE-2026-95274
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium (PTS)bookworm150.0.7871.100-1~deb12u1vulnerable
bookworm (security)154.0.8037.57-1~deb12u1vulnerable
trixie150.0.7871.181-1~deb13u1vulnerable
trixie (security)153.0.8010.52-1~deb13u1vulnerable
forky153.0.8010.52-1vulnerable
sid154.0.8037.57-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromiumsource(unstable)154.0.8037.57-1

Home - Debian Security - Source (Git)

Source: Microsoft Security Response Center · View original ↗ · proprietary-no-redistribution
Full prose not cached — VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftWindows Server 2012
microsoftWindows Server 2012 (Server Core installation)
microsoftWindows Server 2012 R2
microsoftWindows Server 2012 R2 (Server Core installation)
microsoftMicrosoft Excel 2016 (32-bit edition)
microsoftMicrosoft Excel 2016 (64-bit edition)
microsoftMicrosoft PowerPoint 2016 (32-bit edition)
microsoftMicrosoft PowerPoint 2016 (64-bit edition)
microsoftMicrosoft Word 2016 (32-bit edition)
microsoftMicrosoft Word 2016 (64-bit edition)
microsoftMicrosoft Publisher 2016 (32-bit edition)
microsoftMicrosoft Publisher 2016 (64-bit edition)
microsoftMicrosoft Access 2016 (32-bit edition)
microsoftMicrosoft Access 2016 (64-bit edition)
microsoftMicrosoft Office 2016 (32-bit edition)
microsoftMicrosoft Office 2016 (64-bit edition)
microsoftMicrosoft Outlook 2016 (32-bit edition)
microsoftMicrosoft Outlook 2016 (64-bit edition)
microsoftWindows Server 2016
microsoftOffice Online Server
microsoftWindows 10 Version 1607 for 32-bit Systems
microsoftWindows 10 Version 1607 for x64-based Systems
microsoftWindows Server 2016 (Server Core installation)
microsoftMicrosoft SQL Server 2017 for x64-based Systems (GDR)
microsoftWindows 10 Version 1809 for 32-bit Systems
microsoftWindows 10 Version 1809 for x64-based Systems
microsoftWindows Server 2019
microsoftWindows Server 2019 (Server Core installation)
microsoftMicrosoft Office 2019 for 32-bit editions
microsoftMicrosoft Office 2019 for 64-bit editions

OS impact

windows Windows Affected 1 release
VersionStatusFixed in
— Affected —
debian Debian Mixed 4 releases
VersionStatusFixed in
trixie Fixed 154.0.8037.57-1~deb13u1
sid Fixed 154.0.8037.57-1
forky Fixed 154.0.8037.57-1
bookworm Affected —

References

CWEs

CWE-116

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.