CVE-2026-0905: Insufficient policy enforcement in Network
Chromium: CVE-2026-0905 Insufficient policy enforcement in Network
Other sources
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0905?
CVE-2026-0905 has been classified as high severity due to its impact on insufficient policy enforcement.
How do I fix CVE-2026-0905?
To fix CVE-2026-0905, update Google Chrome to version 144.0.7559.59 or the latest version of Microsoft Edge (Chromium-based).
Which browsers are affected by CVE-2026-0905?
CVE-2026-0905 affects Google Chrome and Microsoft Edge (Chromium-based) browsers.
Is there a known exploit for CVE-2026-0905?
There are currently no public reports indicating an active exploit for CVE-2026-0905.
What are the potential impacts of CVE-2026-0905?
The potential impacts of CVE-2026-0905 may include unauthorized access to sensitive information due to insufficient policy enforcement.