Description
Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Cross-origin data disclosure
Action: Patch Immediately
AI Analysis

Impact

A behavioral flaw in the scrolling logic of Google Chrome versions before 155.0.8059.39 allows a malicious extension, installed by a remote attacker, to trick the browser into revealing data from a different origin. The vulnerability is an Information Disclosure weakness (CWE‑203) that enables an attacker to read protected information without proper authorization. The Chromium security review rates the issue as Medium severity because the impact is limited to data leakage within the context of an exploited extension and does not grant unrestricted code execution.

Affected Systems

All installations of Google Chrome whose major version is less than 155.0.8059.39, regardless of operating system, are susceptible. The flaw resides in the browser core, not tied to a specific platform or device. Users running older releases are therefore affected until they upgrade to a fixed version.

Risk and Exploitability

The attack can be carried out remotely by a threat actor who persuades a user to install a crafted extension. The exploit does not require privileged access or local compromise and leverages the browser’s cross-origin policy gaps. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploitation yet. Nevertheless, the Medium severity rating and the ease of delivery via an extension warrant timely remediation.

Generated by OpenCVE AI on October 6, 2026 at 21:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 155.0.8059.39 or newer
  • Restrict Chrome extension installation to trusted developers or disable extensions from untrusted sources
  • Apply enterprise policies to block cross‑origin data leakage from extensions

Generated by OpenCVE AI on October 6, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Exposure via Scroll Discrepancy in Chrome

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
Weaknesses CWE-203
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:32.836Z

Reserved: 2026-10-06T16:31:35.696Z

Link: CVE-2026-106210

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:47.413

Modified: 2026-10-06T19:58:37.060

Link: CVE-2026-106210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses