CVE-2026-106187
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 08.10.2026 13:07:02
Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106252
- EPSS 0.3%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 07.10.2026 13:12:11
Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106306
- EPSS 0.13%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 08.10.2026 13:02:08
Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106309
- EPSS 0.24%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 07.10.2026 13:42:37
Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106394
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 07.10.2026 13:40:55
Incomplete cleanup in Glic in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106427
- EPSS 0.16%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 08.10.2026 18:11:30
Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106191
- EPSS 0.33%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 08.10.2026 13:06:36
Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: ...
CVE-2026-106250
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 07.10.2026 21:17:12
Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106312
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 07.10.2026 13:42:28
Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-106317
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 07.10.2026 13:42:05
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)