Description
Incorrect reference resolution in Offline in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Data Exposure
Action: Apply Update
AI Analysis

Impact

The vulnerability is an incorrect reference resolution bug in the Offline mode of Google Chrome on Android that can allow a remote attacker who has compromised the renderer process to retrieve sensitive information by serving a specially crafted HTML page. The weakness, identified as CWE-706, stems from improper validation of user-supplied URLs, which permits the renderer to access underlying references that should be protected. Once exploited, the attacker can read data that may be stored locally or otherwise considered confidential, resulting in a disclosure of private information.

Affected Systems

Affected products include Google Chrome for Android, specifically any build prior to version 155.0.8059.39. Users running older releases of Chrome on Android are vulnerable until the referenced update is installed.

Risk and Exploitability

The vulnerability’s severity is rated medium. Exploitation requires the attacker to first gain compromise of a renderer process, which typically means a malicious web page must be loaded or a preexisting vulnerability must be leveraged. Because the attacker must already control the renderer, the risk of spontaneous exploitation is limited, and the CVE is not listed in the CISA KEV catalog. No EPSS score is reported, so the public exploit probability cannot be quantified. The primary impact is data exposure through crafted HTML pages; no direct denial of service or remote code execution is possible.

Generated by OpenCVE AI on October 6, 2026 at 21:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install Chrome version 155.0.8059.39 or newer on all Android devices to remove the reference resolution flaw.
  • If immediate patch deployment is not possible, disable the Offline mode feature or prevent offline resource access until the fix is installed.
  • Ensure that web content served to renderer processes cannot reference local offline resources by applying strict reference validation checks and enforcing isolation boundaries.

Generated by OpenCVE AI on October 6, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Title Incorrect Reference Resolution Allows Sensitive Data Exposure via Crafted HTML in Google Chrome Offline Mode

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in Offline in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-706
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T19:35:30.703Z

Reserved: 2026-10-06T16:32:17.996Z

Link: CVE-2026-106230

cve-icon Vulnrichment

Updated: 2026-10-06T19:35:15.536Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:49.800

Modified: 2026-10-06T20:17:20.313

Link: CVE-2026-106230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:15:06Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference