CVE-2026-0901: Inappropriate implementation in Blink
Chromium: CVE-2026-0901 Inappropriate implementation in Blink
Other sources
Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0901?
CVE-2026-0901 has been classified with a critical severity level due to its potential impact on user security.
How do I fix CVE-2026-0901?
To fix CVE-2026-0901, update Google Chrome to version 144.0.7559.59 or later, or update Microsoft Edge to the latest version.
Which software is affected by CVE-2026-0901?
CVE-2026-0901 affects Google Chrome versions prior to 144.0.7559.59 and Microsoft Edge versions prior to 144.0.3719.82.
Is CVE-2026-0901 an issue in all browsers?
CVE-2026-0901 specifically affects Chromium-based browsers like Google Chrome and Microsoft Edge.
How was CVE-2026-0901 discovered?
CVE-2026-0901 was discovered during routine security assessments and has been addressed in updates released for affected browsers.