CVE-2026-106398
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 07.10.2026 13:40:47
Incorrect authorization in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106401
- EPSS 0.34%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 07.10.2026 13:40:34
Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106212
- EPSS 0.29%
- Veröffentlicht 06.10.2026 18:41:29
- Zuletzt bearbeitet 08.10.2026 14:07:08
Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106262
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:29
- Zuletzt bearbeitet 07.10.2026 13:53:48
Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: ...
CVE-2026-106292
- EPSS 0.33%
- Veröffentlicht 06.10.2026 18:41:29
- Zuletzt bearbeitet 07.10.2026 13:43:30
Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium...
CVE-2026-106307
- EPSS 0.23%
- Veröffentlicht 06.10.2026 18:41:29
- Zuletzt bearbeitet 08.10.2026 13:01:48
Incorrect authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106375
- EPSS 0.4%
- Veröffentlicht 06.10.2026 18:41:29
- Zuletzt bearbeitet 07.10.2026 13:46:20
Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106229
- EPSS 0.24%
- Veröffentlicht 06.10.2026 18:41:28
- Zuletzt bearbeitet 07.10.2026 18:05:04
UI misrepresentation in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106232
- EPSS 0.24%
- Veröffentlicht 06.10.2026 18:41:28
- Zuletzt bearbeitet 07.10.2026 15:24:54
UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106301
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:28
- Zuletzt bearbeitet 08.10.2026 13:02:13
Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security sev...