VULNERABILITY INTELLIGENCE

CVE-2026-106295

CVSS score4.2 MEDIUM
EPSS probability0.17%
CISA KEVNot currently listed
Published2026-10-06
Last modified2026-10-07
CVSS vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

Description

Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Weakness classification

  • CWE-863: Incorrect Authorization

Primary references