Description
Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Privilege Escalation via DevTools bypass
Action: Immediate Patch
AI Analysis

Impact

An externally controlled reference in Google Chrome’s DevTools component can be supplied by an adversary through crafted network traffic. This flaw, identified as CWE‑610, allows an attacker to bypass system access restrictions enforced by the browser. The vulnerability could potentially enable the attacker to execute privileged actions or access restricted resources within the Chrome environment.

Affected Systems

Google Chrome desktop browsers on Windows, macOS, and Linux prior to update 154.0.8037.57 are affected. All users running an older stable channel version before this release are vulnerable until they apply the update.

Risk and Exploitability

Chromium labels the issue as Medium severity. No EPSS score is currently available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires the victim to interact with or be subjected to malicious crafted traffic, typically via a socially engineered lure. Because the defect resides in a privileged component, the potential impact is the ability to bypass system access controls, but no publicly documented exploit is known at this time.

Generated by OpenCVE AI on September 30, 2026 at 00:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 154.0.8037.57 or later.
  • Verify that automatic updates are enabled or manually download the latest stable release from the official Chrome releases blog.
  • Train users to avoid opening suspicious links or interacting with untrusted web content that may trigger malicious DevTools traffic.

Generated by OpenCVE AI on September 30, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6513-1 chromium security update
History

Wed, 30 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Externally Controlled Reference in Chrome DevTools Allows Bypass of System Access Restrictions

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Weaknesses CWE-610
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T17:31:46.631Z

Reserved: 2026-09-22T05:11:08.360Z

Link: CVE-2026-95376

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:31.620

Modified: 2026-09-29T18:56:13.190

Link: CVE-2026-95376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T01:00:09Z

Weaknesses
  • CWE-610

    Externally Controlled Reference to a Resource in Another Sphere