Description
Incorrect authorization in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch
AI Analysis

Impact

Google Chrome's Omnibox component contains an incorrect authorization check that lets a remote attacker who has already gained control of the renderer process extract sensitive information from a crafted HTML page. The flaw is classified as high severity by Chromium, reflecting the potential for significant data leakage. "Omnibox" refers to the combined address and search bar in Chrome, and any data accessed through it can include browsing history, credentials, or other private context to which the renderer has temporary access.

Affected Systems

Any desktop installation of Google Chrome using a version earlier than 155.0.8059.39 on the Stable channel is impacted. The issue applies to all platforms for which Chrome Stable is distributed, as the Omnibox component is a core part of the user interface across Windows, macOS, and Linux.

Risk and Exploitability

The vulnerability requires the attacker to have already compromised the renderer process, which typically implies a successful local compromise or a complex inter-process attack vector. The CVSS score of 5.3 indicates a medium severity level, and since EPSS data is unavailable and the issue has not been listed in CISA's KEV catalog, the probability of public exploitation is uncertain but the high impact of data disclosure warrants a high-priority response. The fix eliminates the authorization oversight, preventing any further leakage via crafted pages.

Generated by OpenCVE AI on October 7, 2026 at 02:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 155.0.8059.39 or later, which resolves the Omnibox authorization flaw.
  • If an immediate update is not possible, restrict or disable the renderer's privileges to limit the scope of potential data exposure.
  • Avoid loading untrusted or custom HTML content in the Omnibox until the patch is applied.

Generated by OpenCVE AI on October 7, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:15:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in Chrome Omnibox Allows Information Disclosure

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T19:35:31.115Z

Reserved: 2026-10-06T16:36:32.761Z

Link: CVE-2026-106364

cve-icon Vulnrichment

Updated: 2026-10-06T19:35:21.490Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:05.400

Modified: 2026-10-06T20:17:24.220

Link: CVE-2026-106364

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:30:13Z

Weaknesses