CVE-2026-106183
- EPSS 0.26%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 08.10.2026 13:05:24
Missing authorization in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-106263
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 08.10.2026 18:03:43
Improper input validation in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-106295
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 07.10.2026 13:43:17
Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106330
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 07.10.2026 13:48:06
Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106337
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 07.10.2026 13:38:53
UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106404
- EPSS 0.23%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 09.10.2026 15:56:17
Incorrect authorization in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106271
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 08.10.2026 18:03:58
Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)
CVE-2026-106304
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 07.10.2026 18:04:50
Out of bounds read in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106388
- EPSS 0.23%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 07.10.2026 13:41:24
Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106395
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 08.10.2026 17:14:50
Uninitialized resource in Dawn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)