SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78955

MEDIUM · CVSS 6.5 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Google Chrome versions prior to 152.0.7977.65 contain a vulnerability in the Performance APIs that could allow remote attackers to access cross-origin data through a specially crafted HTML page. This issue poses a medium security risk, making it essential for web developers and organizations relying on Chrome for secure browsing to prioritize updates to mitigate potential data exposure.

CVE
CVE-2026-78955
Severity
MEDIUM
CVSS
6.5
EPSS
0.44%
Chrome

Original NVD Description

Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)