Description
Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A missing authorization check in the Actor component of Google Chrome allowed a malicious actor to exploit a crafted HTML page. The flaw lets a remote attacker bypass system access restrictions, effectively elevating privileges without proper permission validation. The weakness is identified as an authorization gap (CWE‑862).

Affected Systems

This vulnerability affects Google Chrome versions earlier than 155.0.8059.39. Any installation of Chrome that has not been upgraded to 155.0.8059.39 or later is potentially exploitable.

Risk and Exploitability

The flaw is low severity according to Chromium, but it can be leveraged through social engineering. A victim must visit a malicious HTML page, after which the attacker can inject malicious content or commands. With no EPSS score available and the vulnerability not listed in the CISA KEV catalog, the modeled exploit probability is uncertain. However, because the attack requires only a crafted page viewed in the browser, the funnel of opportunity is wide and the privileged elevation result is powerful. The impact to confidentiality, integrity, and availability is significant if the attacker gains system-level access.

Generated by OpenCVE AI on October 6, 2026 at 21:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 155.0.8059.39 or later
  • Configure Chrome to automatically apply updates without user intervention
  • For enterprise deployments, enforce policy that requires the patched version to be installed on all user devices

Generated by OpenCVE AI on October 6, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Actor Allows Remote Privilege Escalation via Crafted HTML Page

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-862
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:34.994Z

Reserved: 2026-10-06T16:33:30.502Z

Link: CVE-2026-106250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:52.053

Modified: 2026-10-06T19:57:00.457

Link: CVE-2026-106250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses