CVE-2026-106299
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:36
- Zuletzt bearbeitet 07.10.2026 21:17:13
Improper input validation in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:36
- Zuletzt bearbeitet 06.10.2026 19:57:00
Missing authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-106187
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 07.10.2026 11:17:11
Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106252
- EPSS 0.27%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 07.10.2026 13:12:11
Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106306
- EPSS 0.12%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 07.10.2026 21:17:13
Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106309
- EPSS 0.22%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 07.10.2026 13:42:37
Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106394
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 07.10.2026 13:40:55
Incomplete cleanup in Glic in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106427
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:35
- Zuletzt bearbeitet 07.10.2026 21:17:13
Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106191
- EPSS 0.33%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 07.10.2026 04:17:47
Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: ...
CVE-2026-106250
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 07.10.2026 21:17:12
Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)