Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-95369

Quick assessment

Affected
Google Chrome
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected Version Matrix 1

VendorProduct Version RangeStatus
Google Chrome 154.0.8037.57< 154.0.8037.57 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-95369

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
行为工作流的不恰当实施
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Google Chrome 154.0.8037.57 ~ 154.0.8037.57 -

II. Public POCs for CVE-2026-95369

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-95369

请登录查看更多情报信息。

Security Blog Posts for CVE-2026-95369 (1)

Other References for CVE-2026-95369 (1)

Same Patch Batch · Google · 2026-09-29 · 142 CVEs total

CVE-2026-102242 8.6 HIGH Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases
CVE-2026-102252 6.9 MEDIUM Path Traversal in VMDK Extractor in OSV-SCALIBR
CVE-2026-95320 CVE-2026-95320
CVE-2026-95299 CVE-2026-95299
CVE-2026-95366 CVE-2026-95366
CVE-2026-95351 CVE-2026-95351
CVE-2026-95331 CVE-2026-95331
CVE-2026-95381 CVE-2026-95381
CVE-2026-95382 CVE-2026-95382
CVE-2026-95297 CVE-2026-95297
CVE-2026-95362 CVE-2026-95362
CVE-2026-95302 CVE-2026-95302
CVE-2026-95375 CVE-2026-95375
CVE-2026-95294 CVE-2026-95294
CVE-2026-95376 CVE-2026-95376
CVE-2026-95359 CVE-2026-95359
CVE-2026-95337 CVE-2026-95337
CVE-2026-95330 CVE-2026-95330
CVE-2026-95345 CVE-2026-95345
CVE-2026-95384 CVE-2026-95384

Showing top 20 of 142 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-95369

No comments yet


Leave a comment