Google Security Advisories · October 2026 — Google Security Advisories
228 advisories 228 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2026-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2026-103631

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-103631

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106240

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106240

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106227

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106227

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106239

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106239

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106211

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106211

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106375

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106375

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106197

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-106197

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-102322

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-102322

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106382

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-106382

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106235

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106235

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106268

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106268

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106233

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106233

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-103628

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-103628

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106374

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106374

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106228

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Me...

CVEs:CVE-2026-106228

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106372

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106372

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106329

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106329

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106194

GoogleCoalition ESS < 30%HIGH2026-10-06

Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted ...

CVEs:CVE-2026-106194

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106190

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106190

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106417

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106417

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106401

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106401

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106414

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity...

CVEs:CVE-2026-106414

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106281

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106281

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106298

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106298

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106419

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106419

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106200

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106200

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106193

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106193

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106191

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106191

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106247

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106247

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106292

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106292

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106373

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106373

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106335

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106335

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106383

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106383

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106241

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severi...

CVEs:CVE-2026-106241

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106323

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security seve...

CVEs:CVE-2026-106323

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-103626

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security se...

CVEs:CVE-2026-103626

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-103630

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-103630

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106378

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106378

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106293

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106293

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106220

GoogleCoalition ESS < 30%HIGH2026-10-06

Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106220

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-103625

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-103625

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106234

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

CVEs:CVE-2026-106234

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106204

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

CVEs:CVE-2026-106204

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106225

GoogleCoalition ESS < 30%HIGH2026-10-06

Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106225

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106203

GoogleCoalition ESS < 30%HIGH2026-10-06

Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106203

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106269

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106269

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106221

GoogleCoalition ESS < 30%HIGH2026-10-06

Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106221

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106252

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106252

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106283

GoogleCoalition ESS < 30%HIGH2026-10-06

Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106283

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106291

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106291

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106315

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106315

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106421

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106421

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106411

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106411

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106423

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106423

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106257

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106257

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106278

GoogleCoalition ESS < 30%HIGH2026-10-06

Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106278

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106318

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106318

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106248

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106248

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-103623

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-103623

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-103622

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-103622

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106238

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106238

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106393

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106393

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106212

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106212

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106387

GoogleCoalition ESS < 30%HIGH2026-10-06

Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106387

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106207

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106207

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106230

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect reference resolution in Offline in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Med...

CVEs:CVE-2026-106230

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-49878

Open SourceCoalition ESS < 30%HIGH2026-10-05

In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2026-49878

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-103624

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium sec...

CVEs:CVE-2026-103624

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106223

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106223

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106215

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106215

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106206

GoogleCoalition ESS < 30%HIGH2026-10-06

Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-106206

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106181

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106181

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106308

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106308

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106409

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium s...

CVEs:CVE-2026-106409

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106222

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-106222

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106205

GoogleCoalition ESS < 30%HIGH2026-10-06

Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106205

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106201

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106201

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106189

GoogleCoalition ESS < 30%HIGH2026-10-06

Code injection in ReaderMode in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106189

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106231

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106231

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106377

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106377

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106183

GoogleCoalition ESS < 30%HIGH2026-10-06

Missing authorization in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-106183

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106256

GoogleCoalition ESS < 30%HIGH2026-10-06

Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106256

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-55265

Open SourceCoalition ESS < 30%MEDIUM2026-10-05

In multiple functions of PduParser.java, there is a possible out of bounds read due to a missing bounds check. This could lead to a remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55265

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-103627

GoogleCoalition ESS < 30%HIGH2026-10-02

Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-103627

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106237

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106237

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106274

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect reference resolution in Browser in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106274

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106371

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106371

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106249

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106249

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106309

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106309

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106314

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106314

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106229

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106229

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106255

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106255

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106232

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106232

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-58835

Open SourceCoalition ESS < 30%HIGH2026-10-05

In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58835

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-106426

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106426

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106412

GoogleCoalition ESS < 30%HIGH2026-10-06

Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML pa...

CVEs:CVE-2026-106412

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106217

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106217

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106184

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106184

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106202

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106202

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106325

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect reference resolution in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106325

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106310

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106310

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-55280

Open SourceCoalition ESS < 30%HIGH2026-10-05

In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55280

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-106264

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Missing authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106264

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106242

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Information leak in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-106242

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106388

GoogleCoalition ESS < 30%HIGH2026-10-06

Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106388

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106307

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106307

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106226

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Improper input validation in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106226

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106209

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106209

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106301

GoogleCoalition ESS < 30%HIGH2026-10-06

Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security sever...

CVEs:CVE-2026-106301

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106198

GoogleCoalition ESS < 30%HIGH2026-10-06

Missing authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106198

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106196

GoogleCoalition ESS < 30%HIGH2026-10-06

Missing authorization in Navigation in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106196

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-58865

Open SourceCoalition ESS < 30%HIGH2026-10-05

In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2026-58865

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-106188

GoogleCoalition ESS < 30%HIGH2026-10-06

Confused deputy in SignIn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106188

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106236

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-106236

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-103421

Open SourceCoalition ESS < 30%HIGH2026-10-03

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficien...

CVEs:CVE-2026-103421

Affected products

ProductStatusVendorPackageEcosystem
WPMobile.App – Android and iOS App Builder (WordPress plugin: wpappninja) affected WPMobile.App — —
Upstream advisory

CVE-2026-106394

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incomplete cleanup in Glic in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106394

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106312

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)

CVEs:CVE-2026-106312

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106303

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Observable discrepancy in Autofill AI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium securit...

CVEs:CVE-2026-106303

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106185

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Improper input validation in Viz in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106185

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106379

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106379

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106245

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106245

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106263

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Improper input validation in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-106263

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106271

GoogleCoalition ESS < 30%HIGH2026-10-06

Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

CVEs:CVE-2026-106271

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106332

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106332

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106179

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106179

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106199

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect authorization in Actor in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106199

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106182

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106182

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106380

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106380

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106302

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106302

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106224

GoogleCoalition ESS < 30%LOW2026-10-06

Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106224

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106195

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-106195

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106390

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106390

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106270

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106270

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106321

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106321

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106330

GoogleCoalition ESS < 30%HIGH2026-10-06

Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106330

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106304

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Out of bounds read in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106304

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106336

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Observable discrepancy in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106336

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106180

GoogleCoalition ESS < 30%LOW2026-10-06

Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106180

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106246

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106246

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106415

GoogleCoalition ESS < 30%HIGH2026-10-06

Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106415

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-103621

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-103621

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106277

GoogleCoalition ESS < 30%HIGH2026-10-06

Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106277

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106392

GoogleCoalition ESS < 30%HIGH2026-10-06

Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106392

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106402

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-106402

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-103629

GoogleCoalition ESS < 30%CRITICAL2026-10-02

Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-103629

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106285

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106285

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-105223

Open SourceCoalition ESS < 30%CRITICAL2026-10-05

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate ...

CVEs:CVE-2026-105223

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-client affected maclof — —
Upstream advisory

CVE-2026-106305

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106305

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106317

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106317

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106276

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106276

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106338

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in PictureInPicture in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106338

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106210

GoogleCoalition ESS < 30%LOW2026-10-06

Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-106210

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106337

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106337

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106282

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106282

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106265

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106265

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106322

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Open redirect in AppManifest in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106322

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106260

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106260

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106275

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106275

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106395

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in Dawn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106395

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106398

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106398

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106290

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106290

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106273

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106273

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106258

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-106258

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106208

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Missing authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-106208

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106400

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106400

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106311

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106311

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106406

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106406

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106187

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106187

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106262

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Me...

CVEs:CVE-2026-106262

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106416

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-106416

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106251

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-106251

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106316

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-106316

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106339

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106339

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106213

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Race condition in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106213

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106420

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-106420

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106244

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-106244

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106324

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106324

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106253

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-106253

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106320

GoogleCoalition ESS < 30%CRITICAL2026-10-06

Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106320

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106391

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in WebShare in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106391

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106284

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Out of bounds read in Printing in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to read memory outside the sandbox via a crafted HTML page. (Chromi...

CVEs:CVE-2026-106284

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106424

GoogleCoalition ESS < 30%HIGH2026-10-06

Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-106424

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106328

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)

CVEs:CVE-2026-106328

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106250

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106250

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106288

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Missing authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106288

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106295

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106295

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106410

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106410

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106299

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Improper input validation in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106299

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106272

GoogleCoalition ESS < 30%MEDIUM2026-10-06

UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-106272

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106300

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Race condition in CacheStorage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-106300

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106259

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106259

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106296

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Improper privilege management in UI in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106296

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106427

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106427

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106214

GoogleCoalition ESS < 30%HIGH2026-10-06

Information leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)

CVEs:CVE-2026-106214

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106413

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106413

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106306

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-106306

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106186

GoogleCoalition ESS < 30%HIGH2026-10-06

Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)

CVEs:CVE-2026-106186

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106192

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Information leak in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via physical access. (Chromium security severity: Low)

CVEs:CVE-2026-106192

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106243

GoogleCoalition ESS < 30%HIGH2026-10-06

Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)

CVEs:CVE-2026-106243

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106279

GoogleCoalition ESS < 30%HIGH2026-10-06

Incorrect reference resolution in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a local program. (Chromium sec...

CVEs:CVE-2026-106279

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106313

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Incorrect authorization in Browser in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)

CVEs:CVE-2026-106313

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106254

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)

CVEs:CVE-2026-106254

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-106326

GoogleCoalition ESS < 30%MEDIUM2026-10-06

Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)

CVEs:CVE-2026-106326

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-28640

Open SourceCoalition ESS < 30%HIGH2026-10-05

In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. Use...

CVEs:CVE-2026-28640

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-106399

GoogleCoalition ESS < 30%LOW2026-10-06

Out of bounds read in Skia in Google Chrome prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to potentially read memory via a crafted file. (Chromium security severity: Low)

CVEs:CVE-2026-106399

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google — —
Upstream advisory

CVE-2026-28647

Open SourceCoalition ESS < 30%HIGH2026-10-05

In updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2026-28647

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-28641

Open SourceCoalition ESS < 30%HIGH2026-10-05

In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges neede...

CVEs:CVE-2026-28641

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-28625

Open SourceCoalition ESS < 30%HIGH2026-10-05

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28625

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-45524

Open SourceCoalition ESS < 30%HIGH2026-10-05

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2026-45524

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-58815

Open SourceCoalition ESS < 30%HIGH2026-10-05

In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58815

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-55286

Open SourceCoalition ESS < 30%HIGH2026-10-05

In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2026-55286

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-55269

Open SourceCoalition ESS < 30%HIGH2026-10-05

In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2026-55269

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-55266

Open SourceCoalition ESS < 30%HIGH2026-10-05

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55266

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-49937

Open SourceCoalition ESS < 30%HIGH2026-10-05

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2026-49937

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-49933

Open SourceCoalition ESS < 30%HIGH2026-10-05

In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution privile...

CVEs:CVE-2026-49933

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-28648

Open SourceCoalition ESS < 30%HIGH2026-10-05

In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28648

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-58880

Open SourceCoalition ESS < 30%HIGH2026-10-05

In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2026-58880

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-55270

Open SourceCoalition ESS < 30%HIGH2026-10-05

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55270

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-58841

Open SourceCoalition ESS < 30%HIGH2026-10-05

In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2026-58841

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-58859

Open SourceCoalition ESS < 30%HIGH2026-10-05

In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58859

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-58854

Open SourceCoalition ESS < 30%HIGH2026-10-05

In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58854

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-58856

Open SourceCoalition ESS < 30%MEDIUM2026-10-05

In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction i...

CVEs:CVE-2026-58856

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-58834

Open SourceCoalition ESS < 30%MEDIUM2026-10-05

In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interactio...

CVEs:CVE-2026-58834

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-100148

GoogleEPSS <= 49%HIGH2026-10-03

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reviews[].text' parameter in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes...

CVEs:CVE-2026-100148

Affected products

ProductStatusVendorPackageEcosystem
Rich Showcase for Google Reviews affected — — —
Upstream advisory

CVE-2026-49885

Open SourceEPSS <= 49%HIGH2026-10-05

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-49885

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Android affected Google — —
Upstream advisory

CVE-2026-49880

Open SourceEPSS <= 49%HIGH2026-10-05

In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2026-49880

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

CVE-2026-28667

Open SourceEPSS <= 49%MEDIUM2026-10-05

In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28667

Affected products

ProductStatusVendorPackageEcosystem
android affected google — —
Upstream advisory

GHSA-g7fw-3gjp-g5hf

GoogleAll remainingHIGH2026-10-05

OpenClaw: Channel read actions could skip target allowlists

Affected products

ProductStatusVendorPackageEcosystem
feishu affected openclaw @openclaw/feishu —
googlechat affected openclaw @openclaw/googlechat —
matrix affected openclaw @openclaw/matrix —
msteams affected openclaw @openclaw/msteams —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.