CVE-2026-106244
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 08.10.2026 12:17:14
Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-106335
- EPSS 0.33%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 07.10.2026 13:47:53
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106415
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:19
- Zuletzt bearbeitet 07.10.2026 13:10:55
Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106217
- EPSS 0.24%
- Veröffentlicht 06.10.2026 18:41:18
- Zuletzt bearbeitet 07.10.2026 20:49:17
Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106225
- EPSS 0.31%
- Veröffentlicht 06.10.2026 18:41:18
- Zuletzt bearbeitet 08.10.2026 01:23:36
Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:18
- Zuletzt bearbeitet 06.10.2026 19:57:00
Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Me...
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:18
- Zuletzt bearbeitet 06.10.2026 19:57:00
Missing authorization in FullScreen in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium se...
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:18
- Zuletzt bearbeitet 06.10.2026 19:57:00
Incorrect authorization in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:18
- Zuletzt bearbeitet 06.10.2026 19:57:00
Missing authorization in BrowserTag in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security sever...
CVE-2026-106223
- EPSS 0.28%
- Veröffentlicht 06.10.2026 18:41:17
- Zuletzt bearbeitet 08.10.2026 01:24:01
Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)