CVE-2026-0905Active Exploitation(apple / chrome)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-30: 1PoC Mentioned / Linked · 2026-01-30: 1Active Exploitation · 2026-01-30: 1Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-30: 101-30
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • RagingCISO@CisoRaging77913
    Active Exploitation

    CVE-2026-0905, 0906, 0907: Triple CVSS 9.8 in Edge. Visit malicious page → owned. No click, no auth. Microsoft patched it. You didn't update because "legacy intranet app breaks." Congrats, your compatibility excuse is now the attacker's front door.

    Post summary

    The post details that CVE‑2026‑0905/06/07 in Microsoft Edge, rated CVSS 9.8, is actively exploited via a malicious page with no click or authentication, and Microsoft has issued a patch.

    0000056
    4 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more