CVE-2026-0906: Critical severity Google Chrome vulnerability
Chromium: CVE-2026-0906 Incorrect security UI
Other sources
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0906?
CVE-2026-0906 has been categorized with a high severity rating due to its impact on the security user interface.
How do I fix CVE-2026-0906?
To mitigate CVE-2026-0906, users should update their Google Chrome to version 144.0.7559.59 or newer, or update Microsoft Edge to a version that includes the security fix.
Which software is affected by CVE-2026-0906?
CVE-2026-0906 affects Google Chrome versions below 144.0.7559.59 and Microsoft Edge (Chromium-based) versions prior to the latest security updates.
Is there a workaround for CVE-2026-0906?
There are no recommended workarounds for CVE-2026-0906; the best action is to apply the available updates.
What type of vulnerability is CVE-2026-0906?
CVE-2026-0906 is classified as an incorrect security UI issue, which may mislead users about the security state of the web page.