CVE-2026-91742
Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium)
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.22%
- CWE
- CWE-441
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-83548 — A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
- CVE-2025-68667 — Conduit-derived homeservers are affected by a Confused Deputy and Improper Input Validation issue
- CVE-2026-87582 — Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised th
- CVE-2025-64125 — Nuvation Energy nCloud Client-to-Client Communication
- CVE-2026-24471 — Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')
- CVE-2025-25306 — Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
- CVE-2022-39361 — Metabase vulnerable to Remote Code Execution via H2
- CVE-2021-32783 — Authorization bypass in Contour