Description
Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Unauthorized Data Access
Action: Patch
AI Analysis

Impact

The vulnerability stems from an incorrect authorization check in Chrome's Bluetooth implementation. A remote attacker can craft an HTML page that accesses the Bluetooth API without proper permission, allowing the attacker to read sensitive information such as device identifiers or pairing details. The flaw is classified as CWE‑863, Missing Authorization Checks, and the Chromium severity rating is medium.

Affected Systems

Products affected are versions of Google Chrome before 155.0.8059.39. The issue applies to all platforms that support the Bluetooth API in Chrome, including desktop operating systems. Users running any pre‑155.0.8059.39 release are potentially vulnerable until they upgrade to a fixed build.

Risk and Exploitability

Although no EPSS score is available and the vulnerability is not listed in CISA's KEV, the CVSS score of 8.8 indicates high severity and a significant exploitation risk. The attack can be performed over the network by hosting a malicious web page that triggers the unauthorized Bluetooth access. The lack of an official workaround means that the only practical defense is to apply the vendor patch or otherwise restrict Bluetooth usage via policies.

Generated by OpenCVE AI on October 7, 2026 at 02:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Chrome 155.0.8059.39 or newer.
  • Restrict Chrome's Bluetooth API via policy or flag to prevent web pages from accessing Bluetooth without explicit permission.
  • Monitor and block sites that attempt to use Bluetooth by using network level controls or extensions that deny such API usage.

Generated by OpenCVE AI on October 7, 2026 at 02:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 02:30:00 +0000

Type Values Removed Values Added
Title Bluetooth authorization bypass in Chrome allows sensitive info leak via crafted web page

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:25:51.477Z

Reserved: 2026-10-06T16:35:00.375Z

Link: CVE-2026-106314

cve-icon Vulnrichment

Updated: 2026-10-06T20:17:06.544Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:59.673

Modified: 2026-10-06T21:17:11.830

Link: CVE-2026-106314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T02:15:10Z

Weaknesses