CVE-2026-95292 Overview
CVE-2026-95292 is an incorrect authorization vulnerability in the Safe Browsing component of Google Chrome. The flaw affects Chrome desktop versions prior to 154.0.8037.57. A remote attacker can bypass system access restrictions by delivering crafted network traffic to a target browser. The issue is tracked under CWE-863: Incorrect Authorization and was addressed in the Chrome Stable channel update. Chromium classifies the internal severity as Low, while the NVD scoring places it in the medium range due to the network-reachable attack surface.
Critical Impact
Remote attackers can bypass Safe Browsing authorization checks through crafted network traffic, undermining a control that normally blocks malicious sites and downloads.
Affected Products
- Google Chrome for Desktop versions prior to 154.0.8037.57
- Chromium-based browsers incorporating the vulnerable Safe Browsing component
- Downstream distributions that had not yet merged the Stable channel fix
Discovery Timeline
- 2026-09-29 - CVE-2026-95292 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-95292
Vulnerability Analysis
The vulnerability resides in Chrome's Safe Browsing subsystem, which is responsible for evaluating URLs, downloads, and network resources against Google's threat intelligence lists. Safe Browsing enforces access decisions before content is rendered or executed by the browser. Because the authorization check is implemented incorrectly, a remote attacker can influence the decision path with specifically shaped network traffic. The result is that content or requests that should be blocked are permitted, weakening a protective layer that end users rely on transparently.
Exploitation requires high attack complexity, meaning the attacker must control network conditions or response content in a specific way. No authentication or user interaction is required, and the impact is limited to partial confidentiality and integrity loss without affecting availability.
Root Cause
The root cause is an authorization logic error [CWE-863] in the Safe Browsing code path. Rather than a memory safety defect, the flaw stems from the component granting access under conditions that should have been denied. See the Chromium Issue Tracker Entry for the upstream discussion.
Attack Vector
The attack is delivered over the network. An attacker either hosts a malicious endpoint the victim browser contacts or manipulates in-path traffic to a legitimate service. By crafting responses that the Safe Browsing check evaluates incorrectly, the attacker bypasses the restriction that would otherwise flag or block the resource. No verified public proof-of-concept code is available, so the exploitation mechanism is described in prose only. Refer to the Google Chrome Desktop Update advisory for release details.
Detection Methods for CVE-2026-95292
Indicators of Compromise
- Chrome desktop installations reporting a version string below 154.0.8037.57 in enterprise inventory data
- Browser telemetry showing successful navigation to URLs that Safe Browsing lists should have blocked
- Unexpected downloads of executable content from domains recently added to threat intelligence feeds
Detection Strategies
- Query endpoint inventory sources for Chrome versions and flag hosts still running builds prior to 154.0.8037.57
- Correlate proxy and DNS logs with public Safe Browsing categorizations to identify sessions where blocking should have triggered but did not
- Monitor for outbound connections to newly registered domains or known phishing infrastructure originating from Chrome processes
Monitoring Recommendations
- Ingest browser version telemetry into a centralized data lake and alert on drift from the patched baseline
- Enable extended URL and download logging on web proxies to reconstruct sessions after the fact
- Track Chrome update compliance in weekly patch reporting until the fleet is fully remediated
How to Mitigate CVE-2026-95292
Immediate Actions Required
- Upgrade all Chrome desktop installations to 154.0.8037.57 or later
- Force a browser relaunch through enterprise management tooling to ensure the updated binary is loaded
- Verify that automatic updates are enabled and functioning on managed endpoints
Patch Information
Google addressed the issue in the Chrome Stable channel release documented in the Google Chrome Desktop Update advisory. Administrators using Chromium-based browsers should confirm that their vendor has merged the corresponding upstream fix referenced in the Chromium Issue Tracker Entry.
Workarounds
- Enforce network-layer URL filtering and DNS security controls that operate independently of the browser's Safe Browsing check
- Restrict outbound access from user endpoints to a vetted allowlist where feasible
- Deploy secure web gateway inspection to compensate for reduced browser-side authorization enforcement until patching completes
# Verify Chrome version on Linux and macOS endpoints
google-chrome --version
# Windows: query the installed version via the registry
reg query "HKLM\Software\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
