CVE-2026-106302
- EPSS 0.21%
- Veröffentlicht 06.10.2026 18:41:23
- Zuletzt bearbeitet 07.10.2026 13:43:06
UI misrepresentation in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106311
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:23
- Zuletzt bearbeitet 07.10.2026 13:42:32
Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106392
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:23
- Zuletzt bearbeitet 07.10.2026 13:41:09
Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106416
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:23
- Zuletzt bearbeitet 07.10.2026 13:10:49
Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-106253
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:22
- Zuletzt bearbeitet 07.10.2026 13:12:33
Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-106279
- EPSS 0.09%
- Veröffentlicht 06.10.2026 18:41:22
- Zuletzt bearbeitet 07.10.2026 13:44:22
Incorrect reference resolution in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a local program. (Chromium s...
CVE-2026-106402
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:22
- Zuletzt bearbeitet 07.10.2026 13:40:26
Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:22
- Zuletzt bearbeitet 08.10.2026 17:10:33
Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-106198
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:21
- Zuletzt bearbeitet 08.10.2026 16:17:02
Missing authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106261
- EPSS 0.24%
- Veröffentlicht 06.10.2026 18:41:21
- Zuletzt bearbeitet 09.10.2026 18:15:03
Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)