CVE-2026-106422

NONE
Updated Oct 06, 2026
Google
Parameter Value
Affected Versions before 155.0.8059.39
Type CWE-863 (Incorrect Authorization)
Vendor Google
Public PoC No

Incorrect authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)