CVE-2026-95311
CRITICALDescription
Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Is your site exposed to CVE-2026-95311?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| chrome |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2026-95311? +
How severe is CVE-2026-95311? +
What products are affected by CVE-2026-95311? +
How do I check if I'm vulnerable to CVE-2026-95311? +
Related Vulnerabilities
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series …
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to …
Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access …
SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access …
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation …