Description
Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to sensitive data via DataTransfer
Action: Immediate Update
AI Analysis

Impact

Missing authorization checks in the DataTransfer API allow a remote attacker who has compromised the renderer process to craft an HTML page that reads sensitive information such as clipboard contents or user input stored in DataTransfer objects. This flaw, classified as CWE-862, effectively bypasses Chrome’s intended privacy controls and can expose confidential data to the attacker.

Affected Systems

Google Chrome desktop users running any version prior to 155.0.8059.39, on any supported operating system, are vulnerable. The issue is limited to the stable channel of Chrome and does not affect beta or dev releases beyond that version threshold.

Risk and Exploitability

The vulnerability carries a medium severity score of 5.3 on the CVSS framework, and the EPSS score is not available. It is not listed in the CISA KEV catalog, indicating no documented public exploitation. An attacker would need to first gain control of a renderer process—most likely via a separate vulnerability such as cross-site scripting—then serve a malicious HTML page that abuses the unprotected DataTransfer API. While the exploitation path is non-trivial, the moderate CVSS rating and lack of known public exploits suggest a moderate risk to affected users.

Generated by OpenCVE AI on October 6, 2026 at 21:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 155.0.8059.39 or later using the built‑in update mechanism.
  • Ensure that Chrome’s sandboxing and renderer process isolation features are enabled and not overridden by custom policies.
  • If an immediate update is not possible, deploy a browser policy that blocks or restricts the use of the DataTransfer API for cross‑origin data transfers to mitigate the exposure.

Generated by OpenCVE AI on October 6, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via DataTransfer in Google Chrome

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T19:35:30.573Z

Reserved: 2026-10-06T16:37:31.006Z

Link: CVE-2026-106388

cve-icon Vulnrichment

Updated: 2026-10-06T19:35:13.718Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:08.073

Modified: 2026-10-06T20:17:25.043

Link: CVE-2026-106388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:00:08Z

Weaknesses