Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.1 Browsers CVE-2026-95287 CVE-2026-95309

Google Chrome Patches Two Medium-Severity Vulnerabilities (CVE-2026-95287, CVE-2026-95309)

Google has released Chrome 154.0.8037.57 to fix a site isolation bypass and a UI spoofing issue on iOS. Both are rated medium or lower severity by Chromium and require attacker-controlled conditions or user interaction to exploit.

Synthesized by AI from 3 sources · updated 2 hours ago

AI summary

Google has shipped a Stable Channel update for Chrome, version 154.0.8037.57, addressing two vulnerabilities disclosed in the vendor's release notes. One affects navigation and site isolation on desktop platforms, while the other concerns UI spoofing on Chrome for iOS. Both issues require some form of attacker precondition or user interaction and are not currently known to be exploited in the wild.

What happened

Google published a Stable Channel update for Chrome on desktop fixing two vulnerabilities. CVE-2026-95287 is a missing authorization issue in Chrome's Navigation component that could allow an attacker who has already compromised the renderer process to bypass site isolation using a crafted HTML page. CVE-2026-95309 is a UI misrepresentation issue in Chrome's Mobile component on iOS, which could allow a remote attacker to spoof UI elements via a crafted HTML page.

Technical cause

CVE-2026-95287 is classified under CWE-862 (Missing Authorization) and arises in the Navigation component; it requires that an attacker has already compromised the renderer process as a precondition before the site isolation bypass can occur. CVE-2026-95309 is classified under CWE-451 (User Interface (UI) Misrepresentation of Critical Information) and affects the Mobile component specifically on iOS, where a crafted HTML page can cause spoofing of UI elements.

Why it matters

Site isolation is a core security boundary in Chrome designed to prevent one website from accessing data belonging to another. A bypass, even one requiring a compromised renderer as a precondition, weakens this defense-in-depth mechanism. The UI spoofing issue on iOS could be used to mislead users about the content or origin of a page, which may facilitate phishing or other deceptive attacks. Chromium rated the first issue as Medium severity and the second as Low severity.

Who is affected

CVE-2026-95287 affects Google Chrome on desktop platforms prior to version 154.0.8037.57. CVE-2026-95309 affects Google Chrome on iOS prior to the same version.

Affected versions

Both vulnerabilities affect Google Chrome versions prior to 154.0.8037.57. The fact package does not specify a lower bound for the affected range, so the full extent of affected prior versions is not detailed in the available sources.

Fixes and mitigation

Google has fixed both vulnerabilities in Chrome version 154.0.8037.57, released via the Stable Channel update for desktop. Users and administrators should ensure Chrome is updated to this version or later.

Recommended action

Update Google Chrome to version 154.0.8037.57 or later as soon as possible. Chrome typically updates automatically, but users and administrators managing fleets should verify the installed version and force an update check if necessary, particularly for iOS deployments affected by CVE-2026-95309.

PatchBriefing score

4.1 / 10 · Medium

Official CVSS: 5.4

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Why this score

Both vulnerabilities received a PatchBriefing score of 4.1, reflecting their CVSS base score of 5.4 (moderate impact, low attack complexity, but requiring user interaction) and the fact that no known exploitation or public exploit code exists. The score includes a small contribution for the unauthenticated remote attack vector and for Chrome's broad product popularity, but is not elevated by any evidence of active exploitation or EPSS data, which was not available for either entry.

Affected versions

≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched

Reported fixes

Google has fixed both vulnerabilities in Chrome version 154.0.8037.57, released via the Stable Channel update for desktop. Users and administrators should ensure Chrome is updated to this version or later.

How this was built

3 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Patches Two Medium-Severity Vulnerabilities (CVE-2026-95287, CVE-2026-95309)
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email