CVE-2026-106363
Missing authorization in FullScreen in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-862
- Published
- 2026-10-06
- Last modified
- 2026-10-08
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-106323 — Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leve
- CVE-2026-106387 — Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging s
- CVE-2026-106225 — Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social en
- CVE-2026-106367 — Missing authorization in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveragin
- CVE-2026-106194 — Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compro
- CVE-2026-106191 — Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the
- CVE-2026-106198 — Missing authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromise
- CVE-2026-106271 — Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised t