Description
Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)
Published: 2026-10-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability is an incomplete cleanup in the Proxy Auth handling code in Google Chrome. An attacker adjacent to the affected system could craft network traffic that triggers the flaw and causes the browser to expose sensitive data that should have been discarded. The high severity rating indicates that this information disclosure could expose credentials or other confidential data exchanged between the user and a proxy server.

Affected Systems

Google Chrome versions prior to 155.0.8059.39 are affected. This includes the stable channel releases up to that build.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity vulnerability. No EPSS score is available, and the vulnerability is not listed in CISA's KEV catalog, but the medium severity rating still highlights the potential for information disclosure. The flaw requires an attacker to be able to send crafted Proxy-Authorization packets on the network segment where the target Chrome instance resides. Because the attacker must be adjacent, the threat surfaces mainly in shared or untrusted network environments. Once the condition is met, the browser leaks data that should have been purged.

Generated by OpenCVE AI on October 7, 2026 at 02:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later.
  • Configure network security controls to block or monitor forged Proxy-Authorization headers that target Chrome instances.
  • Regularly audit and enforce Chrome update policy across all endpoints to ensure all installations remain current.

Generated by OpenCVE AI on October 7, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:15:00 +0000

Type Values Removed Values Added
Title Proxy Authentication Cleanup Failure Allows Adjacent Attacker to Leak Sensitive Data

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)
Weaknesses CWE-459
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:40:10.967Z

Reserved: 2026-10-06T16:33:13.409Z

Link: CVE-2026-106243

cve-icon Vulnrichment

Updated: 2026-10-06T20:40:05.985Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:17:51.253

Modified: 2026-10-07T13:52:32.837

Link: CVE-2026-106243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:30:13Z

Weaknesses