CVE-2026-0905Sensitive Information Exposure in Google Chrome

Severity
9.8CRITICALNVD
EPSS
0.0%
top 90.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateJan 27

Description

Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome144.0.7559.59144.0.7559.59
NVDgoogle/chrome< 144.0.7559.59+1
Debianchromium/chromium< 144.0.7559.59-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-jq9g-gj4g-q8w7: Insufficient policy enforcement in Network in Google Chrome prior to 1442026-01-20
CVEList
CVE-2026-0905: Insufficient policy enforcement in Network in Google Chrome prior to 1442026-01-20
OSV
CVE-2026-0905: Insufficient policy enforcement in Network in Google Chrome prior to 1442026-01-20

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-09052026-01-27
Red Hat
chromium-browser: Insufficient policy enforcement in Network2026-01-13
Microsoft
Chromium: CVE-2026-0905 Insufficient policy enforcement in Network2026-01-13
Debian
CVE-2026-0905: chromium - Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559....2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-0905 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0905 — Sensitive Information Exposure | cvebase