Description
Missing authorization in Media in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Disclosure
Action: Update Chrome
AI Analysis

Impact

A missing authorization check in the media subsystem of Google Chrome on Windows permits a remote attacker who has already compromised the renderer process to read sensitive information through a specially crafted web page. The flaw is an authorization weakness that allows confidential data to be accessed without proper permission checks.

Affected Systems

Google Chrome running on Windows, specifically all releases prior to version 155.0.8059.39. The vulnerability manifests only before the update that addressed the missing authorization in the media component.

Risk and Exploitability

The flaw is not listed in the CISA KEV catalog and no EPSS score is available, suggesting it is not widely exploited at this time. Because exploitation requires an attacker to first compromise the renderer process—typically achieved via local code execution or a trusted site—this represents a lower severity risk in heavily sandboxed environments, but once the renderer is compromised, the attacker can freely access sensitive data through crafted pages. The impact is a confidentiality breach of data transmitted or displayed by Chrome's media features. The likely attack path involves a malicious web page that triggers the media component while the renderer process privileges remain high, bypassing normal authorization controls.

Generated by OpenCVE AI on October 6, 2026 at 21:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (155.0.8059.39 or later) to fix the missing authorization check
  • Configure Chrome to restrict media feature access only to trusted sites if policy allows
  • Ensure the Chrome renderer process remains sandboxed and enforce strict sandbox policies to limit potential exploitation

Generated by OpenCVE AI on October 6, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chrome Windows Media Missing Authorization Allows Sensitive Data Exposure

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Media in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-862
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T19:32:55.954Z

Reserved: 2026-10-06T16:36:16.834Z

Link: CVE-2026-106355

cve-icon Vulnrichment

Updated: 2026-10-06T19:32:51.334Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:04.380

Modified: 2026-10-06T20:17:23.733

Link: CVE-2026-106355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:15:06Z

Weaknesses