CVE-2026-25740 - Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-b...

CVE-2026-25740 - Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-b...

CVE ID : CVE-2026-25740 Published : Feb. 9, 2026, 9:15 p.m. | 1 hour, 7 minutes ago Description : captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can run arbitrary commands with the CAP_NET_RAW capability (binding to privileged ports, spoofing localhost traffic from privileged services...). This vulnerability is fixed in 25.11 and 26.05. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Feb. 9, 2026