CVE-2026-106427 — Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a p…
Description
Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
Affected
- Vendor
- Product
- chrome
Versions
- < 155.0.8059.39
Stated as the source expressed them.
References
Related threats
same CWE or vendorCVE-2026-107336 — Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive r…
CVE-2026-107336 · 6h ago
CVE-2026-107282 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.
CVE-2026-107282 · 1d ago
CVE-2026-107232 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.
CVE-2026-107232 · 1d ago
CVE-2026-102255 — A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
CVE-2026-102255 · 1d ago
CVE-2026-106487 — Backstage is an open framework for building developer portals.
CVE-2026-106487 · 2d ago
CVE-2026-106462 — Backstage is an open framework for building developer portals.
CVE-2026-106462 · 2d ago