OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-106424

MEDIUM · CVSS 4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A vulnerability in the Audio component of Google Chrome prior to version 155.0.8059.39 allows remote attackers to exploit a compromised renderer process to access memory outside the sandbox through a malicious Chrome extension. This information leak could lead to unauthorized data exposure, making it critical for users and organizations relying on Chrome to prioritize updates to mitigate potential risks. Security teams should focus on patching affected systems to prevent exploitation.

CVE
CVE-2026-106424
Severity
MEDIUM
CVSS
4
EPSS
0.18%
Chrome

Original NVD Description

Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)