CVE-2026-13955: exploitation status and patch state CVE-2026-13955 · CVSS 3.3 LOW · EPSS <1% · patch available
Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Medium)
Is CVE-2026-13955 exploited? Not in the CISA KEV catalog. EPSS puts exploitation in the next 30 days at <1%. Public exploit code: none found in monitored sources. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? What PlainSec published about CVE-2026-13955 Primary sources What this record does not say No affected package data. KEV and EPSS are re-checked daily. Record last updated 2026-08-14.
CVE-2026-13955: exploitation status and patch state CVE-2026-13955 · CVSS 3.3 LOW · EPSS <1% · patch available
Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Medium)
Is CVE-2026-13955 exploited? Not in the CISA KEV catalog. EPSS puts exploitation in the next 30 days at <1%. Public exploit code: none found in monitored sources. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? What PlainSec published about CVE-2026-13955 Primary sources What this record does not say No affected package data. KEV and EPSS are re-checked daily. Record last updated 2026-08-14.