Description
Information leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)
Published: 2026-10-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Leak
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an information leak in the proxy component of Google Chrome on Windows. An attacker who can observe or influence the network traffic adjacent to the system can craft specific packets that cause Chrome to expose sensitive information. The weakness is a classic information disclosure flaw (CWE-200) and is rated high severity by Chromium security team. The impact is limited to the data that Chrome reveals through the proxy path; it does not provide direct code execution or privilege escalation.

Affected Systems

Google Chrome on Windows versions earlier than 155.0.8059.39 are affected. Users running the Stable channel of Chrome on Windows should check their version and upgrade if they are on an earlier build.

Risk and Exploitability

No publicly available EPSS score is reported, but the CVSS score of5.3 indicates a medium severity level for this information disclosure vulnerability. The vulnerability is not listed in CISA’s KEV catalog, indicating no known exploited instances. Attackers would still need local or network proximity to send crafted traffic to the proxy used by Chrome; no remote arbitrary code execution is possible from the information presented.

Generated by OpenCVE AI on October 7, 2026 at 03:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later
  • Enable automatic updates for Chrome to ensure timely patching
  • If an update is unavailable, disable the proxy settings in Chrome or restrict network traffic to the proxy layer to mitigate the leak

Generated by OpenCVE AI on October 7, 2026 at 03:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Title Information Leak in Chrome Proxy on Windows chromium-browser: Information leak in Proxy
References
Metrics threat_severity

None

threat_severity

Important


Wed, 07 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Title Information Leak in Chrome Proxy on Windows

Tue, 06 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Information leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:22:31.840Z

Reserved: 2026-10-06T16:31:40.864Z

Link: CVE-2026-106214

cve-icon Vulnrichment

Updated: 2026-10-06T20:22:24.926Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:47.983

Modified: 2026-10-06T21:17:06.717

Link: CVE-2026-106214

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-06T18:41:08Z

Links: CVE-2026-106214 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:45:10Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor