Description
Cross-site request forgery in ReadingList in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Web origin policy bypass via CSRF
Action: Update Chrome
AI Analysis

Impact

The flaw is a cross‑site request forgery in the ReadingList component of Chrome for Android. A crafted HTML page can force the browser to perform actions that bypass the web origin policy, allowing a remote attacker to send privileged requests on the user’s behalf. The vulnerability has a medium severity rating and could result in unauthorized data access or other malicious behavior.

Affected Systems

Affected versions are any Chrome for Android builds prior to 155.0.8059.39. The issue is specific to the Android platform and impacts all devices running Chrome before this update.

Risk and Exploitability

The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. The likely attack vector is social engineering, where a user must open a malicious webpage or click a link that triggers the ReadingList CSRF. Given the medium severity and absence of publicly known exploits, the immediate risk is moderate; however, users should still prioritize updating Chrome.

Generated by OpenCVE AI on October 6, 2026 at 21:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome for Android to version 155.0.8059.39 or newer.
  • Disable the ReadingList feature on Android devices if it is not required.
  • Educate users to avoid clicking on suspicious links that could exploit CSRF vulnerabilities.

Generated by OpenCVE AI on October 6, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in Chrome ReadingList on Android Enables Web Origin Policy Bypass

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Cross-site request forgery in ReadingList in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-352
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:26.663Z

Reserved: 2026-10-06T16:31:51.332Z

Link: CVE-2026-106216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:48.210

Modified: 2026-10-06T19:58:37.060

Link: CVE-2026-106216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)