CVE-2026-106312
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 07.10.2026 13:42:28
Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-106317
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 07.10.2026 13:42:05
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106344
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 07.10.2026 21:17:13
Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium s...
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 06.10.2026 19:57:00
Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: Low)
- EPSS 0.24%
- Veröffentlicht 06.10.2026 18:41:34
- Zuletzt bearbeitet 06.10.2026 19:57:00
Confused deputy in DeviceBoundSessionCredentials in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106276
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:33
- Zuletzt bearbeitet 07.10.2026 13:48:19
UI misrepresentation in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106338
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:33
- Zuletzt bearbeitet 07.10.2026 13:38:46
UI misrepresentation in PictureInPicture in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106340
- EPSS 0.09%
- Veröffentlicht 06.10.2026 18:41:33
- Zuletzt bearbeitet 06.10.2026 21:17:12
Missing authorization in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via physical access. (Chromium security severity: Low)
CVE-2026-106341
- EPSS 0.32%
- Veröffentlicht 06.10.2026 18:41:33
- Zuletzt bearbeitet 06.10.2026 20:17:23
Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106372
- EPSS 0.31%
- Veröffentlicht 06.10.2026 18:41:33
- Zuletzt bearbeitet 07.10.2026 13:46:49
Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)