Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-95310: Chrome on Debian lets attackers run code via web page

CVE-2026-95310 · published 2 days ago
Summary

A bug in Chrome's ad‑filtering feature can let a specially crafted web page cause the browser to run any program the attacker chooses, breaking the protection that normally keeps web content separate from the rest of the computer. This affects Debian versions of Chromium and Google Chrome older than version 154.0.8037.57. Install the latest updates from your distribution or upgrade Chrome to a newer version as soon as possible.

What to do
  • Update debian chromium to version 154.0.8037.57-1~deb13u1.
  • Update debian chromium to version 154.0.8037.57-1.
  • Update google chrome to version 154.0.8037.57 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian chromium All versions
Debian:13 debian chromium < 154.0.8037.57-1~deb13u1
Fix: upgrade to 154.0.8037.57-1~deb13u1
Debian:14 debian chromium < 154.0.8037.57-1
Fix: upgrade to 154.0.8037.57-1
– google chrome < 154.0.8037.57
Original advisory text
DEBIAN-CVE-2026-95310
Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-416Use After Free
Timeline
Published29 Sep 2026
Updated1 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-95310 · MITRE
Track software like this
Free during beta