Description
Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

This vulnerability is a confused deputy flaw in Google Chrome’s Contextual Tasks. A remote attacker who has already compromised a renderer process can trick the browser into treating a crafted HTML page as a privileged page, thereby bypassing the normal web origin policy. The effect is a privilege escalation that lets the attacker access resources that should be restricted to the privileged page, potentially leading to data theft or further compromise.

Affected Systems

The flaw affects Google Chrome versions before 155.0.8059.39. All users running these older builds are susceptible.

Risk and Exploitability

The exploit requires an attacker to first compromise a renderer process, which typically occurs through malicious web content or a prior vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The Chromium severity assessment is Medium, indicating that while the attack vector is remote, successful exploitation would grant the attacker elevated privileges within the browser context.

Generated by OpenCVE AI on October 6, 2026 at 21:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later, which contains the fix for this issue.
  • If an immediate update is not feasible, disable Contextual Tasks via Chrome’s settings or flags to reduce the attack surface.
  • After applying the update, monitor for anomalous renderer behavior and restrict access to privileged pages from untrusted origins.

Generated by OpenCVE AI on October 6, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title Confused deputy in Chrome Contextual Tasks allows origin policy bypass by compromised renderer

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-441
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:18.923Z

Reserved: 2026-10-06T16:33:57.355Z

Link: CVE-2026-106266

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:54.110

Modified: 2026-10-06T19:57:00.457

Link: CVE-2026-106266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')