Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-95347: Chrome on Mac can run malicious code
CVE-2026-95347 · published 2 days ago
Summary
The Chrome web browser on Mac computers (including the Debian‑packaged Chromium version) can be tricked by specially crafted network data to run code on the computer, bypassing Chrome’s normal security barriers. This could let an attacker take control of the system without the user’s knowledge. Update Chrome to the latest version as soon as possible to protect against this risk.
What to do
- Update debian chromium to version 154.0.8037.57-1~deb13u1.
- Update debian chromium to version 154.0.8037.57-1.
- Update google chrome to version 154.0.8037.57 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | chromium | All versions |
| Debian:13 | debian | chromium |
< 154.0.8037.57-1~deb13u1 Fix: upgrade to 154.0.8037.57-1~deb13u1
|
| Debian:14 | debian | chromium |
< 154.0.8037.57-1 Fix: upgrade to 154.0.8037.57-1
|
| – | chrome | < 154.0.8037.57 |
Original advisory text
DEBIAN-CVE-2026-95347
Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.6
Critical
Type
CWE-416Use After Free
Timeline
Published29 Sep 2026
Updated1 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta