CVE-2026-95301 is an improper authorization vulnerability in Chromium's extensions accessibility automation infrastructure. AutomationEventRouter accepted BindAutomation requests through the RendererAutomationRegistry interface from web renderer processes without verifying that the calling process hosted an enabled extension granted the automation permission. A compromised, site-locked renderer could register an unauthorized automation receiver. While a legitimate chrome.automation consumer was active, accessibility events were broadcast to all registered receivers, allowing the rogue receiver to obtain serialized accessibility trees from other origins and tabs. The exposed data included visible text, non-password form values, ARIA content, and cross-site frame URLs. Password fields were masked. This constitutes a Site Isolation bypass because a renderer could access cross-origin data that should have remained isolated.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chromium/Chrome Site Isolation bypass and sensitive-data disclosure in the extensions automation infrastructure. An attacker who had already compromised a site-locked renderer could register an unauthorized automation receiver and receive accessibility-tree updates from other origins and potentially other profiles while a legitimate chrome.automation consumer was active. Chromium fixed it by validating ProcessMap and automation-permission authorization in AutomationEventRouter::BindForRenderer, terminating unauthorized renderer processes with a bad message.
A Chrome Site Isolation bypass and sensitive-data disclosure in the extensions automation infrastructure. An untrusted compromised renderer could bind the RendererAutomationRegistry without browser-side authorization and receive cross-origin accessibility-tree data, including visible text, non-password form values, ARIA data, and frame URLs, when a legitimate chrome.automation consumer was active. The issue was fixed by validating the calling process against ProcessMap and AutomationInfo, terminating unauthorized renderers with a bad message.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.