Description
Incorrect authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized System Access
Action: Patch
AI Analysis

Impact

An authorization flaw in the Network component of Google Chrome permits a remote attacker who has compromised the renderer process to bypass system access controls through a crafted HTML page. The vulnerability allows the attacker to perform network operations that are normally restricted, potentially exposing sensitive system resources. The weakness maps to CWE‑863, indicating a failure to enforce proper access checks.

Affected Systems

Google Chrome versions prior to 155.0.8059.39 are affected. The flaw exists in the Network module of the browser, impacting all installations of Chrome that have not applied the latest update. Both consumer and enterprise deployments are susceptible if the affected version is used.

Risk and Exploitability

The CVE does not have an EPSS score; no KEV listing is present, implying a moderate exposure level. The attacker must already have control over a renderer process, which typically requires delivering malicious content or exploiting another vulnerability to achieve. Once the renderer is compromised, the attacker can use the flaw to elevate privileges and access the system beyond intended boundaries. Given the medium Chromium severity rating and lack of active exploitation reports, the immediate risk is considered moderate but mitigable by applying the patch.

Generated by OpenCVE AI on October 6, 2026 at 21:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (155.0.8059.39 or newer) to remove the authorization flaw.
  • If immediate update is not possible, enforce Chrome enterprise policies that restrict renderer process capabilities and sandbox network requests to trusted origins.
  • Conduct a review of internal assets for signs of compromised renderer processes and remediate any malicious content or scripts that may have been injected.

Generated by OpenCVE AI on October 6, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in Chrome Network API Allows Bypass of System Access Restrictions

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:29.819Z

Reserved: 2026-10-06T16:34:45.709Z

Link: CVE-2026-106307

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:58.887

Modified: 2026-10-06T19:57:00.457

Link: CVE-2026-106307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:00:08Z

Weaknesses