Common Vulnerabilities and Exposures (CVE)

CVE-2026-106300

Oct 6, 2026 18:41:17 UTC

Race condition in CacheStorage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106267

Oct 6, 2026 18:41:16 UTC

Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106365

Oct 6, 2026 18:41:16 UTC

Missing authorization in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106286

Oct 6, 2026 18:41:15 UTC

Confused deputy in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

CVE-2026-106208

Oct 6, 2026 18:41:15 UTC

Missing authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

CVE-2026-106420

Oct 6, 2026 18:41:15 UTC

Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)

CVE-2026-106324

Oct 6, 2026 18:41:15 UTC

Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106184

Oct 6, 2026 18:41:13 UTC

Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-104945

Oct 6, 2026 18:41:13 UTC

TP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers. An authenticated ONVIF client can submit an excessive number of preset-related elements, causing writes beyond the bounds of fixed-si...

CVE-2026-106379

Oct 6, 2026 18:41:11 UTC

Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106332

Oct 6, 2026 18:41:10 UTC

Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106273

Oct 6, 2026 18:41:10 UTC

Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106202

Oct 6, 2026 18:41:09 UTC

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106231

Oct 6, 2026 18:41:09 UTC

Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106396

Oct 6, 2026 18:41:09 UTC

Improper input validation in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)