CVE-2026-106400
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:27
- Zuletzt bearbeitet 07.10.2026 13:40:40
Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106209
- EPSS 0.23%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 06.10.2026 21:17:06
UI misrepresentation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 06.10.2026 19:58:37
Cross-site request forgery in ReadingList in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106277
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 07.10.2026 13:48:11
Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106284
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 07.10.2026 16:17:36
Out of bounds read in Printing in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to read memory outside the sandbox via a crafted HTML page. (Chro...
CVE-2026-106328
- EPSS 0.16%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 07.10.2026 13:39:02
Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
CVE-2026-106387
- EPSS 0.29%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 06.10.2026 21:17:14
Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106410
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:26
- Zuletzt bearbeitet 07.10.2026 13:40:01
Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106180
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:25
- Zuletzt bearbeitet 07.10.2026 11:17:11
Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106201
- EPSS 0.27%
- Veröffentlicht 06.10.2026 18:41:25
- Zuletzt bearbeitet 07.10.2026 04:17:50
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)