HIGH
chromium-browser: chromium-browser: Incorrect authorization in Navigation
Published Sep 29, 2026
8.8
HIGHCVSS 3.1
EPSS 0.39%
Description
Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected products
-
- Version 154.0.8037.57StatusaffectedConstraints<154.0.8037.57
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Weaknesses (2)
References (7)
- https://access.redhat.com/security/cve/CVE-2026-95355 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543410 Issue Tracking
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-89224 Advisory
- https://issues.chromium.org/issues/508462481
- https://nvd.nist.gov/vuln/detail/CVE-2026-95355
- https://www.cve.org/CVERecord?id=CVE-2026-95355
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Sep 29, 2026
Updated Sep 30, 2026
Reserved Sep 22, 2026
Link CVE-2026-95355
CISA Vulnrichment
Updated Sep 29, 2026
ENISA EUVD
EUVD-2026-89224 Assigner Chrome
Published Sep 29, 2026
Updated Sep 30, 2026
Exploited since n/a
Link EUVD-2026-89224