Description
Improper input validation in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Immediate Update
AI Analysis

Impact

Improper input validation in the Omnibox component of Google Chrome on Android allowed an attacker to craft a malicious HTML page that, when visited, could bypass the browser’s web origin policy. This flaw enabled a remote attacker to potentially read or modify content from other origins that the user was authenticated to, thereby exposing confidential information or enabling further malicious actions. The flaw is identified as CWE‑20, indicating an input validation weakness. The Chromium security team rated the issue as High severity, reflecting the potential impact on user data and privacy.

Affected Systems

The vulnerability affects users of Google Chrome on Android using any version prior to 155.0.8059.39. No specific patch versions are listed, but any Android installation of Chrome before this release is susceptible.

Risk and Exploitability

The exploit requires social engineering; a malicious actor must persuade a user to visit a crafted page for the bypass to occur, implying user interaction. Because the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of exploitation is uncertain but not negligible. The high severity rating suggests a significant risk if exploited, and the cross-origin policy violation can lead to data leakage or unauthorized actions. No publicly documented zero‑day exploit exists as of the release note.

Generated by OpenCVE AI on October 7, 2026 at 02:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Patch Chrome to version 155.0.8059.39 or newer. The October 2026 stable channel update addresses the bug and is available via the Chrome update process or the Android Play Store.
  • Until an official patch is applied, users should avoid clicking on suspicious links or visiting potentially malicious sites that may contain crafted HTML designed to exploit this flaw.
  • Consider configuring Chrome policies on managed devices to restrict or disable the Omnibox preview feature, which can reduce the window of opportunity for the attacker.

Generated by OpenCVE AI on October 7, 2026 at 02:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Chrome Omnibox Allows Remote Web Origin Policy Bypass

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:09.489Z

Reserved: 2026-10-06T16:37:59.054Z

Link: CVE-2026-106396

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:09.023

Modified: 2026-10-06T19:57:00.457

Link: CVE-2026-106396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:30:12Z

Weaknesses
  • CWE-20

    Improper Input Validation