Description
Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure
Action: Update Immediately
AI Analysis

Impact

The vulnerability involves incorrect reference resolution in Chrome's DevTools. A remote attacker who has already compromised the renderer process can use a specially crafted HTML page to read sensitive data that would normally be protected. This flaw enables a confidentiality breach by exposing data visible in the DevTools environment for the compromised process.

Affected Systems

Google Chrome browsers for all platforms. The issue applies to versions prior to 155.0.8059.39; versions 155.0.8059.39 and later contain the fix.

Risk and Exploitability

The weakness relies on an attacker having control over the renderer process; therefore the attack vector is limited to scenarios where the renderer can be compromised locally or via other vulnerabilities. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating a lower known exploitation likelihood. The CVSS score is 5.3, indicating moderate severity, but no EPSS data is available.

Generated by OpenCVE AI on October 7, 2026 at 02:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Chrome update to version 155.0.8059.39 or later. This includes the DevTools reference resolution fix.
  • Disable DevTools for untrusted or internal environments if the feature is not required. In Chrome settings, turn off the Developer Tools privilege for untrusted tabs or contexts.
  • Limit renderer process privileges by ensuring only trusted content is loaded and that renderer isolation policies are active.

Generated by OpenCVE AI on October 7, 2026 at 02:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 03:15:00 +0000

Type Values Removed Values Added
Title Incorrect Reference Resolution in DevTools Allows Sensitive Information Disclosure

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-706
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T19:35:30.990Z

Reserved: 2026-10-06T16:30:02.759Z

Link: CVE-2026-106181

cve-icon Vulnrichment

Updated: 2026-10-06T19:35:19.559Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:44.043

Modified: 2026-10-06T20:17:18.047

Link: CVE-2026-106181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:00:12Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference