Description
Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Authorization bypass via site isolation
Action: Apply Patch
AI Analysis

Impact

Missing authorization controls in the Passwords component of Google Chrome for Android prior to version 155.0.8059.39 allow a remote attacker who has already compromised the renderer process to bypass the browser’s site isolation feature through a specifically crafted HTML page. This vulnerability represents a broken access control flaw (CWE‑862) and was assessed with a medium severity by Chromium. The impact of gaining access to isolated renderer contexts is the potential for cross‑site data leakage, theft of credentials or other sensitive information, and a possible escalation to more serious privileges if combined with other weaknesses.

Affected Systems

Versions of Google Chrome for Android earlier than 155.0.8059.39 are affected. Any device running those builds can be vulnerable to the bypass if a malicious renderer process is introduced into the browsing context.

Risk and Exploitability

The exploit requires the attacker to already compromise the renderer process, meaning lateral or initial access vector is a prerequisite. EPSS data is not available, and the issue is not listed in CISA KEV, implying that widespread exploitation has not yet been observed. However, because the vulnerability bypasses a core isolation mechanism, its potential impact is significant. The CVSS score indicates a medium severity, and the risk is heightened for environments that rely on site isolation for compartmentalizing sensitive web traffic.

Generated by OpenCVE AI on October 6, 2026 at 21:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 155.0.8059.39 or later to apply the authorization fix
  • Enable the "Site Isolation" setting in Chrome’s advanced flags (chrome://flags) to ensure renderer contexts remain segregated
  • If a patch is not immediately available, monitor for and isolate any anomalous renderer processes through Android’s app permissions or enterprise device management policies

Generated by OpenCVE AI on October 6, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via Renderer Process on Android Chrome

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:27.289Z

Reserved: 2026-10-06T16:31:23.738Z

Link: CVE-2026-106205

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:46.840

Modified: 2026-10-06T19:58:37.060

Link: CVE-2026-106205

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:15:06Z

Weaknesses