Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-95340

Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 13.0%
CVSS Severity
CVSS v3 Score 4.3


Contact Us

Shodan ® - All rights reserved