CVE-2026-106295
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 07.10.2026 13:43:17
Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106330
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 07.10.2026 13:48:06
Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106337
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 07.10.2026 13:38:53
UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106352
- EPSS 0.31%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 06.10.2026 21:17:13
Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106404
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:31
- Zuletzt bearbeitet 07.10.2026 20:17:10
Incorrect authorization in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106271
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 07.10.2026 20:17:09
Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)
CVE-2026-106304
- EPSS 0.18%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 07.10.2026 18:04:50
Out of bounds read in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106388
- EPSS 0.21%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 07.10.2026 13:41:24
Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106395
- EPSS 0.19%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 07.10.2026 16:17:38
Uninitialized resource in Dawn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106398
- EPSS 0.17%
- Veröffentlicht 06.10.2026 18:41:30
- Zuletzt bearbeitet 07.10.2026 13:40:47
Incorrect authorization in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)