CVE-2026-95316 — Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program.
Description
Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program. (Chromium security severity: Low)
CVSS v3.1 base metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NLow severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
None
Integrity
A
None
Availability
Affected
- Vendor
- Product
- chrome
Versions
- < 154.0.8037.57
Stated as the source expressed them.
References
Related threats
same CWE or vendorCVE-2026-106436 — The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit.
CVE-2026-106436 · 3h ago
CVE-2026-106427 — Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a p…
CVE-2026-106427 · 2d ago
CVE-2026-106426 — Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox…
CVE-2026-106426 · 2d ago
CVE-2026-106424 — Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory…
CVE-2026-106424 · 2d ago
CVE-2026-106423 — Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafte…
CVE-2026-106423 · 2d ago
CVE-2026-106421 — Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …
CVE-2026-106421 · 2d ago