Description
Missing authorization in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Web origin policy bypass leading to potential data disclosure or unauthorized access
Action: Apply Patch
AI Analysis

Impact

Google Chrome versions prior to 155.0.8059.39 suffer from a missing authorization check in the Animation component, allowing a remote attacker to craft a malicious HTML page that bypasses the browser’s origin policy. This flaw can enable the attacker to read or modify web content from a different origin, potentially exposing sensitive data or enabling further attacks. The weakness corresponds to CWE-862, reflecting an improper authorization flaw. The assigned severity is Medium as reported by Chromium’s security team.

Affected Systems

Google Chrome on any operating system, specifically all releases older than 155.0.8059.39.

Risk and Exploitability

The vulnerability is exploitable from a remote attacker that can deliver a crafted HTML page, such as via a compromised web site or phishing email. Although the EPSS score is not available, the flaw remains unlisted in the CISA KEV catalog, indicating it is not currently a widely known exploited vulnerability. Nevertheless, because the flaw permits origin policy bypass, the potential for malicious exploitation is significant, especially in environments with untrusted web content.

Generated by OpenCVE AI on October 7, 2026 at 02:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 155.0.8059.39 or later, which includes the authorization fix for the Animation component.
  • Deploy the update through your organization’s software update or management system to ensure all endpoints run the patched version.
  • If the update cannot be applied immediately, mitigate risk by disabling the animation feature or applying a policy that blocks animation handling until the browser is patched.

Generated by OpenCVE AI on October 7, 2026 at 02:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 02:30:00 +0000

Type Values Removed Values Added
Title Remote Origin Policy Bypass via Animation in Chrome

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:16.435Z

Reserved: 2026-10-06T16:36:33.662Z

Link: CVE-2026-106365

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:05.507

Modified: 2026-10-06T19:57:00.457

Link: CVE-2026-106365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:15:12Z

Weaknesses