
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0903 is an improper input validation vulnerability in the Downloads component of Google Chrome on Windows, allowing a remote attacker to bypass dangerous file type protections via a malicious file. It was reported by researcher "Azur" on 2025-09-13 and publicly disclosed on January 13, 2026, as part of the Chrome 144 stable channel release. Affected versions include Google Chrome prior to 144.0.7559.59 (Windows/Linux) and 144.0.7559.60 (macOS), as well as Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium), as assessed by CISA-ADP (Chrome Releases, Microsoft MSRC).
The root cause is classified as CWE-20 (Improper Input Validation) within Chrome's Downloads subsystem. Specifically, the vulnerability stems from an "inappropriate implementation" that fails to adequately validate untrusted input, enabling a remote attacker to bypass Chrome's built-in dangerous file type protections — security controls designed to warn users before downloading potentially harmful file types. Exploitation requires user interaction (e.g., visiting a malicious page or clicking a crafted download link), but requires no special privileges. The Chromium issue tracker entry (ID 444803530) is currently restricted pending broad user patching (Chrome Releases).
Successful exploitation allows an attacker to deliver and potentially execute dangerous file types (e.g., executables, scripts) on a victim's system by bypassing Chrome's file type safety warnings, impacting both confidentiality and integrity. The CVSS assessment reflects low confidentiality and integrity impact with no availability impact, consistent with a security UI/filter bypass rather than direct code execution within the browser sandbox. However, the practical risk is elevated because bypassing download protections can serve as a precursor to malware delivery and further system compromise (Chrome Releases).
.exe, .bat, .ps1, or other file types normally blocked by Chrome's download protection) disguised or manipulated to bypass Chrome's file type validation logic..exe, .bat, .ps1, .msi, .vbs, etc.) without triggering browser warnings.Google has released Chrome 144.0.7559.59 for Windows and Linux, and 144.0.7559.60 for macOS, which address this vulnerability. Microsoft has also released a patched version of Edge (Chromium-based) as of January 16, 2026. Users and administrators should update Chrome and Edge to the latest available versions immediately, and enable automatic updates where possible to ensure rapid deployment. No configuration-based workaround is available; patching is the only remediation (Chrome Releases, Microsoft MSRC).
The Chrome 144 release, which includes the fix for CVE-2026-0903, received broad coverage from security news outlets including SecurityOnline, CybersecurityNews, GBHackers, and Forbes, primarily focusing on the overall batch of 10 security fixes rather than this specific CVE (SecurityOnline, Forbes). The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Chrome 144 could allow for arbitrary code execution. Community reaction has been routine, with no notable controversy or significant researcher commentary specific to this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."