6.5
CVE-2026-95330
- EPSS 0.31%
- Veröffentlicht 29.09.2026 17:31:48
- Zuletzt bearbeitet 01.10.2026 17:29:28
- Erkennungen
Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.214 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
CWE-754 Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html
https://issues.chromium.org/issues/517163294