CVE-2026-106185
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 08.10.2026 13:04:45
Improper input validation in Viz in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106189
- EPSS 0.27%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 08.10.2026 13:06:50
Code injection in ReaderMode in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106224
- EPSS 0.21%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 08.10.2026 01:23:51
Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106244
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 08.10.2026 12:17:14
Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-106335
- EPSS 0.33%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 07.10.2026 13:47:53
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106415
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 07.10.2026 13:10:55
Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106217
- EPSS 0.24%
- Veröffentlicht 06.10.2026 18:41:18
- Zuletzt bearbeitet 07.10.2026 20:49:17
Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106225
- EPSS 0.31%
- Veröffentlicht 06.10.2026 18:41:18
- Zuletzt bearbeitet 08.10.2026 01:23:36
Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106223
- EPSS 0.28%
- Veröffentlicht 06.10.2026 18:41:17
- Zuletzt bearbeitet 08.10.2026 01:24:01
Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106241
- EPSS 0.33%
- Veröffentlicht 06.10.2026 18:41:17
- Zuletzt bearbeitet 07.10.2026 13:53:07
Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security seve...