Description
Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the handling of animation data in Google Chrome prior to version 155.0.8059.39. A crafted HTML page can trigger an information leak that exposes sensitive data to a remote attacker. This flaw is categorized as information exposure, allowing the attacker to read data beyond intended boundaries, which could include user credentials or local content. The impact is disclosure of private information rather than code execution or denial of service.

Affected Systems

The affected product is Google Chrome before version 155.0.8059.39. Users running any older Chrome release are potentially vulnerable. The issue was fixed in Chrome 155.0.8059.39, the latest stable release at the time of the patch.

Risk and Exploitability

The CVSS score is not provided in the CVE data, and an EPSS score is not available, indicating no precise exploit probability estimate. Chrome describes the flaw as medium severity, and it is not present in the CISA KEV catalog, so no publicly documented exploits are known. The likely attack vector is a remote web page that a user visits or a local file that contains crafted HTML; user interaction is required to load the page so that the animation flaw can be leveraged to read data outside the normal scope.

Generated by OpenCVE AI on October 6, 2026 at 22:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Chrome update (155.0.8059.39 or later) on all affected devices.
  • Configure Chrome to install security updates automatically, ensuring future patches are applied without manual intervention.
  • If the patch cannot be applied immediately, prevent use of legacy Chrome versions on corporate devices and filter or block untrusted web sites that could host malicious HTML exploiting the animation flaw.

Generated by OpenCVE AI on October 6, 2026 at 22:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Title Information Leak via Animation in Google Chrome

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-200
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:29.670Z

Reserved: 2026-10-06T16:36:07.669Z

Link: CVE-2026-106348

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:03.383

Modified: 2026-10-06T19:57:00.457

Link: CVE-2026-106348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:15:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor