CVE-2026-106409
- EPSS 0.26%
- Veröffentlicht 06.10.2026 18:41:33
- Zuletzt bearbeitet 07.10.2026 13:40:12
Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium...
CVE-2026-106207
- EPSS 0.29%
- Veröffentlicht 06.10.2026 18:41:32
- Zuletzt bearbeitet 07.10.2026 04:17:50
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106210
- EPSS 0.2%
- Veröffentlicht 06.10.2026 18:41:32
- Zuletzt bearbeitet 07.10.2026 11:17:12
Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-106254
- EPSS 0.07%
- Veröffentlicht 06.10.2026 18:41:32
- Zuletzt bearbeitet 07.10.2026 13:16:38
Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
CVE-2026-106321
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:32
- Zuletzt bearbeitet 07.10.2026 13:38:40
Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106351
- EPSS 0.21%
- Veröffentlicht 06.10.2026 18:41:32
- Zuletzt bearbeitet 06.10.2026 20:17:23
Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:32
- Zuletzt bearbeitet 06.10.2026 19:57:00
Missing authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106386
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:32
- Zuletzt bearbeitet 07.10.2026 15:17:11
Uninitialized resource in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106183
- EPSS 0.26%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 06.10.2026 21:17:05
Missing authorization in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-106263
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 07.10.2026 20:17:09
Improper input validation in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)