CVE-2026-106270
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:40
- Zuletzt bearbeitet 07.10.2026 13:48:25
Incorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106288
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:40
- Zuletzt bearbeitet 07.10.2026 21:17:12
Missing authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106305
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:40
- Zuletzt bearbeitet 07.10.2026 13:42:46
UI misrepresentation in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106343
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:40
- Zuletzt bearbeitet 07.10.2026 11:17:15
Improper state validation in Autofill AI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106350
- EPSS 0.25%
- Veröffentlicht 06.10.2026 18:41:40
- Zuletzt bearbeitet 06.10.2026 21:17:13
Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:40
- Zuletzt bearbeitet 06.10.2026 19:57:00
Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
CVE-2026-106179
- EPSS 0.21%
- Veröffentlicht 06.10.2026 18:41:39
- Zuletzt bearbeitet 06.10.2026 21:17:05
UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106237
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:39
- Zuletzt bearbeitet 07.10.2026 15:15:55
Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106249
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:39
- Zuletzt bearbeitet 07.10.2026 13:39:36
Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:39
- Zuletzt bearbeitet 06.10.2026 19:57:00
Improper input validation in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted Chrome extension. (Chromium security severity: Lo...