OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-106387

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability in Google Chrome on iOS prior to version 155.0.8059.39 allows remote attackers to exploit missing authorization, potentially exposing sensitive information through a specially crafted HTML page. This high-severity flaw, rated 8.8 on the CVSS scale, poses a significant risk, particularly to users who may be targeted through social engineering tactics. Organizations and individuals using affected versions of Chrome should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-106387
Severity
HIGH
CVSS
8.8
EPSS
0.29%
Chrome

Original NVD Description

Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)