CVE-2026-106406
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:21
- Zuletzt bearbeitet 07.10.2026 13:40:21
Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106196
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:20
- Zuletzt bearbeitet 08.10.2026 13:03:40
Missing authorization in Navigation in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:20
- Zuletzt bearbeitet 06.10.2026 19:57:00
Incorrect authorization in USB in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:20
- Zuletzt bearbeitet 06.10.2026 19:57:00
Incorrect authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106407
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:20
- Zuletzt bearbeitet 08.10.2026 13:17:14
Incorrect authorization in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:20
- Zuletzt bearbeitet 06.10.2026 19:57:00
Protection mechanism failure in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106414
- EPSS 0.34%
- Veröffentlicht 06.10.2026 18:41:20
- Zuletzt bearbeitet 07.10.2026 13:13:12
Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severi...
CVE-2026-106185
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 08.10.2026 13:04:45
Improper input validation in Viz in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106189
- EPSS 0.27%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 08.10.2026 13:06:50
Code injection in ReaderMode in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106224
- EPSS 0.21%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 08.10.2026 01:23:51
Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)