CVE-2026-0906 is a critical vulnerability affecting Google Chrome on Android, specifically versions prior to 144.0.7559.59. It allows a remote attacker to spoof the Omnibox (URL bar) content through a crafted HTML page, impacting Google, Apple, Linux, and Microsoft products. Rated with a CVSS score of 9.8 (Critical), this vulnerability has a low attack complexity and requires no user interaction, potentially leading to high confidentiality, integrity, and availability impacts. The FAUCET Risk Score is 97/100, indicating significant risk. While there is no evidence of active exploitation (not in KEV or Hot List), and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community discussion, with 12 mentions, indicating high awareness among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 144.0.7559.59, < 144.0.7559.59CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 144.0.7559.59CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 144.0.7559.60CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.