Skip to main content
Vulnerability Database/CVE-2026-95287

CVE-2026-95287: Google Chrome Auth Bypass Vulnerability

CVE-2026-95287 is an authorization bypass flaw in Google Chrome Navigation that enables attackers to break site isolation. This post explains the technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2026-95287 Overview

CVE-2026-95287 is a missing authorization vulnerability in the Navigation component of Google Chrome. The flaw affects Chrome versions prior to 154.0.8037.57 and permits a remote attacker who has already compromised the renderer process to bypass site isolation using a crafted HTML page. Chromium classifies the security severity as Medium. Site isolation is a foundational Chrome sandboxing feature that separates web content from different origins into distinct renderer processes. Bypassing it undermines a defense-in-depth boundary that protects cross-origin data.

Critical Impact

An attacker who already controls a compromised renderer process can bypass Chrome's site isolation boundary, exposing cross-origin content to unauthorized access via crafted HTML.

Affected Products

  • Google Chrome for Desktop prior to 154.0.8037.57
  • Chromium-based browsers that inherit the vulnerable Navigation code path
  • Downstream distributions bundling pre-patch Chromium builds

Discovery Timeline

  • 2026-09-29 - CVE-2026-95287 published to the National Vulnerability Database
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-95287

Vulnerability Analysis

The vulnerability resides in Chrome's Navigation logic and is categorized as a missing authorization defect [CWE-862]. Chrome's site isolation model enforces that each site runs in its own renderer process. Cross-process navigation decisions must verify that the requesting renderer is permitted to act on behalf of a given origin. This authorization check is missing or insufficient in the affected navigation path.

Exploitation requires a prerequisite: the attacker must already have compromised a renderer process, typically through a separate memory corruption or logic flaw. Once inside a renderer, the attacker crafts an HTML page that triggers the navigation flow. This produces cross-origin effects the isolation model should prevent. The result is limited confidentiality and integrity impact on data belonging to other sites the user is browsing.

Root Cause

The root cause is an absent authorization enforcement step in the Navigation code path. When the browser process handles navigation requests originating from a renderer, it must confirm the renderer holds valid capabilities for the target origin. Chrome fails this check under specific conditions, allowing an attacker-controlled renderer to influence navigation state across the isolation boundary. Full technical details are tracked in Chromium Issue #495529018.

Attack Vector

The attack chain is two-stage. First, the attacker gains code execution inside a Chrome renderer process through an independent vulnerability or a hostile web resource. Second, the attacker serves a crafted HTML page that triggers the flawed navigation logic to bypass site isolation. User interaction is required. This is a sandbox-adjacent bypass rather than a direct remote code execution primitive.

No verified public exploit code is available. See the Google Chrome Stable Update advisory for release details.

Detection Methods for CVE-2026-95287

Indicators of Compromise

  • Chrome renderer processes performing unexpected cross-origin navigation transitions inconsistent with user interaction
  • Browser telemetry showing anomalous navigation events preceded by renderer instability or prior exploit indicators
  • Endpoints running Chrome builds older than 154.0.8037.57 after the vendor patch release

Detection Strategies

  • Inventory installed browser versions across the fleet and flag Chrome installations below 154.0.8037.57
  • Correlate browser crash telemetry and renderer sandbox violations with subsequent suspicious network activity
  • Monitor for delivery of crafted HTML pages via web proxies and email gateways, especially from low-reputation domains

Monitoring Recommendations

  • Ingest browser and endpoint telemetry into a centralized data lake for cross-source correlation of exploitation attempts
  • Track update compliance for Chrome and Chromium-based browsers using endpoint management tooling
  • Alert on execution of child processes spawned by Chrome that deviate from baseline behavior

How to Mitigate CVE-2026-95287

Immediate Actions Required

  • Update Google Chrome to version 154.0.8037.57 or later on all managed endpoints
  • Restart browser sessions after patch deployment to ensure the fix takes effect
  • Audit browser version inventory and prioritize systems that handle sensitive cross-origin workflows

Patch Information

Google addressed CVE-2026-95287 in the Chrome Stable channel release 154.0.8037.57. Patch details are available in the Google Chrome Stable Update announcement. Chromium-based browser vendors should ship equivalent fixes from upstream. Verify downstream browsers such as Microsoft Edge, Brave, and Opera have merged the corresponding patch.

Workarounds

  • Enforce automatic Chrome updates through enterprise policy to reduce exposure windows
  • Restrict browsing to trusted sites via allowlists where operationally feasible
  • Deploy web filtering to block delivery of untrusted HTML content from low-reputation sources
bash
# Verify installed Chrome version on Linux endpoints
google-chrome --version

# Windows: check version via registry
reg query "HKLM\Software\Google\Chrome\BLBeacon" /v version

# Enforce auto-update via Chrome enterprise policy (Linux example)
# /etc/opt/chrome/policies/managed/update_policy.json
# {
#   "UpdateDefault": 1,
#   "AutoUpdateCheckPeriodMinutes": 60
# }

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.