Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-95284: Chrome or Chromium on Android can run malicious code
CVE-2026-95284 · published 2 days ago
Summary
A problem in the Chrome browser on Android and the Chromium version used on Debian lets a specially crafted web page cause the browser to run unwanted programs. This could give an attacker control over the device. Install the latest browser updates (Chrome 154.0.8037.57 or newer and the current Debian Chromium package) to fix the issue.
What to do
- Update debian chromium to version 154.0.8037.57-1~deb13u1.
- Update debian chromium to version 154.0.8037.57-1.
- Update google chrome to version 154.0.8037.57 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | chromium | All versions |
| Debian:13 | debian | chromium |
< 154.0.8037.57-1~deb13u1 Fix: upgrade to 154.0.8037.57-1~deb13u1
|
| Debian:14 | debian | chromium |
< 154.0.8037.57-1 Fix: upgrade to 154.0.8037.57-1
|
| – | chrome | < 154.0.8037.57 |
Original advisory text
DEBIAN-CVE-2026-95284
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
References
- https://security-tracker.debian.org/tracker/CVE-2026-95284 Vendor Advisory
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_... Release Notes Vendor Advisory
- https://issues.chromium.org/issues/556435507 Permissions Required
Severity
9.6
Critical
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published29 Sep 2026
Updated1 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta