CVE-2026-0904: Medium Incorrect security UI in Digital Credentials
Chromium: CVE-2026-0904 Incorrect security UI in Digital Credentials
Other sources
Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0904?
CVE-2026-0904 has been classified with a moderate severity, impacting the security UI in Digital Credentials within Chromium-based browsers.
How do I fix CVE-2026-0904?
To fix CVE-2026-0904, ensure you update your Google Chrome or Microsoft Edge (Chromium-based) to the latest version available.
Which browsers are affected by CVE-2026-0904?
CVE-2026-0904 affects Google Chrome versions prior to 144.0.7559.59 and Microsoft Edge (Chromium-based) versions earlier than the latest update.
Is CVE-2026-0904 exploitable remotely?
CVE-2026-0904 is considered potentially exploitable, emphasizing the importance of timely updates to mitigate risks.
Who is responsible for addressing CVE-2026-0904?
Google and Microsoft are responsible for addressing CVE-2026-0904, as it affects their Chromium-based browsers.