Description
Incorrect reference resolution in Browser in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Disclosure
Action: Immediate Patch
AI Analysis

Impact

An incorrect reference resolution flaw in Google Chrome on macOS permits a remote attacker, using social engineering to luring a user to a specially crafted HTML page, to gain access to sensitive information that the browser would normally protect. The flaw is classified as Improper Access Control (CWE‑706).

Affected Systems

The vulnerability is present in all Google Chrome for macOS versions earlier than 155.0.8059.39. Versions 155.0.8059.40 and later contain the fix, so any machine running the outdated browser remains susceptible.

Risk and Exploitability

The issue carries a CVSS score of 8.8, indicating high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires only a malicious web page and a user’s interaction, the probability of exploitation depends largely on successful social engineering; once triggered, the attacker can expose private information to which the browser should have restricted access.

Generated by OpenCVE AI on October 7, 2026 at 02:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install Chrome 155.0.8059.40 or later on all macOS devices.
  • Configure enterprise policies or use the Chrome Update for Mac to enforce automatic updates across all user accounts.
  • Inform users about the threat and advise them to avoid visiting suspicious or unexpected web pages.

Generated by OpenCVE AI on October 7, 2026 at 02:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Title Incorrect Reference Resolution Enables Sensitive Data Disclosure on macOS Chrome

Tue, 06 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in Browser in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-706
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:25:51.606Z

Reserved: 2026-10-06T16:34:06.202Z

Link: CVE-2026-106274

cve-icon Vulnrichment

Updated: 2026-10-06T20:17:08.377Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:55.023

Modified: 2026-10-06T21:17:09.603

Link: CVE-2026-106274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T02:45:10Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference