CVE-2026-106216
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 09.10.2026 17:55:56
Cross-site request forgery in ReadingList in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106277
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 07.10.2026 13:48:11
Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106284
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 08.10.2026 18:03:20
Out of bounds read in Printing in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to read memory outside the sandbox via a crafted HTML page. (Chro...
CVE-2026-106328
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 07.10.2026 13:39:02
Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
CVE-2026-106387
- EPSS 0.29%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 08.10.2026 17:16:03
Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106410
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 07.10.2026 13:40:01
Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106180
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:25
- Zuletzt bearbeitet 08.10.2026 13:05:53
Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106201
- EPSS 0.27%
- Veröffentlicht 06.10.2026 18:41:25
- Zuletzt bearbeitet 08.10.2026 12:13:59
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106206
- EPSS 0.28%
- Veröffentlicht 06.10.2026 18:41:25
- Zuletzt bearbeitet 08.10.2026 12:12:12
Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-106228
- EPSS 0.36%
- Veröffentlicht 06.10.2026 18:41:25
- Zuletzt bearbeitet 07.10.2026 18:04:58
Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: ...