VULNERABILITY INTELLIGENCE
CVE-2026-106295
CVSS score4.2 MEDIUM
EPSS probability0.17%
CISA KEVNot currently listed
Published2026-10-06
Last modified2026-10-07
CVSS vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L
Description
Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weakness classification
- CWE-863: Incorrect Authorization
Primary references
- chrome-cve-admin@google.com — Release Notes, Vendor Advisory
- chrome-cve-admin@google.com — Permissions Required