CVE-2026-95352 Overview
CVE-2026-95352 is an incorrect authorization vulnerability in the DevTools component of Google Chrome versions prior to 154.0.8037.57. The flaw allows a remote attacker to bypass the web origin policy through a crafted Chrome extension. Exploitation requires user interaction and social engineering to convince the target to install the malicious extension. Google's Chromium project classifies the underlying security severity as Low, while NVD rates the issue as Medium. The weakness is tracked under CWE-863: Incorrect Authorization.
Critical Impact
A malicious Chrome extension can bypass same-origin restrictions using DevTools, exposing cross-origin data and enabling limited tampering when a victim is convinced to install the extension.
Affected Products
- Google Chrome desktop versions prior to 154.0.8037.57
- Chromium-based browsers that inherit the vulnerable DevTools code path
- Environments permitting user installation of third-party Chrome extensions
Discovery Timeline
- 2026-09-29 - CVE-2026-95352 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-95352
Vulnerability Analysis
The vulnerability resides in Chrome DevTools, the browser's built-in developer instrumentation layer. DevTools exposes privileged APIs that allow inspection and modification of page content, network traffic, and script execution. Under normal conditions, extensions using the chrome.devtools.* APIs must respect the web origin policy that isolates content from different sites.
An authorization check within the DevTools code path fails to correctly enforce origin boundaries when invoked from a crafted extension. As a result, an attacker-controlled extension can access or manipulate resources belonging to origins it should not reach. The scope is limited to confidentiality and integrity effects; availability is not impacted according to the published CVSS vector.
Root Cause
The root cause is an incorrect authorization decision within DevTools APIs exposed to Chrome extensions. The affected component approves requests that should be denied when the requesting extension operates outside its authorized origin scope, breaking the same-origin trust boundary that Chrome enforces elsewhere in the browser.
Attack Vector
Exploitation follows a network-based, user-assisted path. The attacker distributes a crafted Chrome extension, typically through social engineering such as fake developer tools, productivity add-ons, or sideloaded packages. Once the victim installs and enables the extension, the extension invokes the vulnerable DevTools functionality to bypass the web origin policy. No elevated privileges are required from the attacker beyond the permissions granted to a standard extension.
Because user interaction is required and the attack relies on convincing a target to install untrusted code, exploitation at scale depends on the attacker's distribution channel rather than a remote-network primitive. See the Chromium Issue Tracker Entry and Google Chrome Update Announcement for vendor details.
Detection Methods for CVE-2026-95352
Indicators of Compromise
- Chrome extensions requesting the devtools permission from sources outside the official Chrome Web Store
- Unexpected extension installations on managed endpoints, particularly those bundling developer-oriented capabilities
- Browser telemetry showing extension-initiated access to cross-origin resources without a corresponding user navigation
Detection Strategies
- Inventory installed Chrome extensions across the fleet and flag any declaring devtools_page in their manifest
- Compare Chrome version strings reported by endpoints against the fixed release 154.0.8037.57 or later
- Review enterprise browser reporting logs for extension install events tied to social-engineering delivery vectors such as phishing email or malvertising
Monitoring Recommendations
- Enable Chrome Enterprise reporting to centralize extension inventory and version telemetry
- Monitor endpoint process telemetry for chrome.exe child processes and unusual extension activity
- Correlate browser events with email and web-proxy logs to identify the delivery path for suspicious extensions
How to Mitigate CVE-2026-95352
Immediate Actions Required
- Update Google Chrome to version 154.0.8037.57 or later on all managed endpoints
- Restart Chrome after updating to ensure the patched DevTools binary is loaded
- Audit installed extensions and remove any that were sideloaded or sourced from untrusted publishers
Patch Information
Google addressed CVE-2026-95352 in the Chrome Stable channel release 154.0.8037.57. Refer to the Google Chrome Update Announcement for the full advisory and the Chromium Issue Tracker Entry for engineering context. Chromium-derived browsers should apply their vendor's corresponding update once available.
Workarounds
- Restrict extension installation using the ExtensionInstallAllowlist and ExtensionInstallBlocklist Chrome enterprise policies
- Block installation of extensions that declare the devtools_page manifest key where not required for business use
- Educate users on social-engineering tactics used to distribute malicious extensions outside the Chrome Web Store
# Configuration example: Chrome enterprise policy to force minimum version and constrain extensions
# Windows registry (HKLM\Software\Policies\Google\Chrome)
ExtensionInstallAllowlist = [
"<approved-extension-id-1>",
"<approved-extension-id-2>"
]
ExtensionInstallBlocklist = ["*"]
ExtensionSettings = {
"*": {
"installation_mode": "blocked",
"runtime_blocked_hosts": ["<all_urls>"]
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
