
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0905 is an insufficient policy enforcement vulnerability in the Network component of Google Chrome, classified with Chromium security severity: Medium. It affects Google Chrome versions prior to 144.0.7559.59 (Linux/Windows) and 144.0.7559.60 (macOS), as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Google on 2025-12-02 and publicly disclosed on January 13, 2026, when Chrome 144 was released to the stable channel. CISA-ADP has assigned a CVSS v3.1 base score of 9.8 (Critical), though Google's own severity rating is Medium (Chrome Release Notes, Microsoft MSRC).
The root cause is insufficient policy enforcement in Chrome's Network component (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). According to the NVD description, the flaw allows an attacker who has obtained a network log file to potentially extract sensitive information from that file — indicating the vulnerability relates to improper handling or protection of network log data rather than direct remote code execution. The Chromium issue tracker entry (issues.chromium.org/issues/465466773) is restricted pending broad user updates. The discrepancy between Google's Medium severity rating and CISA-ADP's CVSS 9.8 Critical score suggests the CISA-ADP vector may reflect a worst-case theoretical assessment rather than the practical exploitation scenario described (Chrome Release Notes, Microsoft MSRC).
Successful exploitation requires an attacker to first obtain a Chrome network log file, after which they may extract potentially sensitive information such as URLs, headers, or other network traffic details captured in the log. The practical confidentiality impact is limited to the contents of the network log rather than full system compromise, despite the high CVSS score assigned by CISA-ADP. There is no evidence that integrity or availability are directly impacted by this specific vulnerability as described (Chrome Release Notes).
chrome://net-export/ or command-line flags such as --log-net-log=netlog.json, generating a JSON file containing network activity.chrome://net-internals/#import or a JSON parser to extract sensitive data such as request URLs, HTTP headers, cookies, authentication tokens, or other network metadata that may be insufficiently protected due to the policy enforcement flaw.netlog.json) in user directories or temporary folders, particularly if net-logging was not intentionally enabled by the user.--log-net-log or --net-log-capture-mode flags in process creation logs, indicating net-logging may have been enabled without user knowledge.Update Google Chrome to version 144.0.7559.59 or later (Linux/Windows) and 144.0.7559.60 or later (macOS) immediately. Microsoft Edge (Chromium-based) users should apply the corresponding patch released by Microsoft on January 16, 2026. As a precautionary measure, organizations should avoid enabling Chrome net-logging (--log-net-log) in production environments and ensure that any existing network log files are stored securely with restricted access. Chromium-based distributions (Debian, Fedora, openSUSE, Alpine, etc.) have also released updated packages and should be updated accordingly (Chrome Release Notes, Microsoft MSRC).
The Chrome 144 release received broad coverage from security news outlets including Forbes, CyberSecurityNews, GBHackers, and CIS, primarily focused on the full set of 10 security fixes in the release rather than CVE-2026-0905 specifically. The CIS issued an advisory noting that multiple vulnerabilities in Chrome 144 could allow for arbitrary code execution. Security researchers and community members noted the significant discrepancy between Google's Medium severity rating for this CVE and the CVSS 9.8 Critical score assigned by CISA-ADP, with discussion on platforms including Mastodon and Bluesky (CIS Advisory, Chrome Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."