Description
Open redirect in AppManifest in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass via Open Redirect
Action: Apply Patch
AI Analysis

Impact

Google Chrome versions earlier than 155.0.8059.39 contain an open redirect flaw in the AppManifest facility. An attacker can craft a malicious HTML page that, when a user clicks a link, redirects the browser to an untrusted site while circumventing Chrome’s origin‑policy checks. The flaw is classified as medium severity by Chromium’s internal scoring, and is a classic example of URL redirection that can be leveraged for phishing or social engineering attacks.

Affected Systems

The vulnerability affects Google Chrome users running any version older than 155.0.8059.39. All operating systems that support this Chrome release are potentially exposed, because the AppManifest redirect logic is identical across platforms.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, so publicly documented exploitation data is sparse. The CVSS is not disclosed in the available data, but the medium severity rating indicates a limited but meaningful risk. Exploitation requires the victim to visit a malicious webpage and click a link, which is a common social‑engineering scenario. The attack vector is remote via crafted HTML; an attacker does not need privileged access to the victim’s machine to trigger the redirect.

Generated by OpenCVE AI on October 6, 2026 at 21:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later, which removes the AppManifest open‑redirect flaw.
  • If available in your organization’s Chrome policy set, disable the AppManifest feature to block redirect processing altogether.
  • Train users to recognize and avoid clicking suspicious links that may trigger unintended redirects.

Generated by OpenCVE AI on October 6, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
Title Open Redirect in AppManifest Enables Web Origin Policy Bypass in Chrome

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Open redirect in AppManifest in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-601
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:24.716Z

Reserved: 2026-10-06T16:35:17.779Z

Link: CVE-2026-106322

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:00.450

Modified: 2026-10-06T19:57:00.457

Link: CVE-2026-106322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:30:10Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')