{"Cloud":true,"Homeassistant":true,"Plex":true,"Proxmox1":true,"Proxmox2":true,"SecurityAlerts":[],"CveAlerts":[{"CvssScore":"0.0","CveId":"CVE-2026-58068","Description":"Affected products:\nAgent for Windows\n\nDescription:\nThis vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system.","Link":"https://www.veeam.com/kb4902","Title":"CVE-2026-58068 [0.0] This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system."},{"CvssScore":"0.0","CveId":"CVE-2026-106426","Description":"Affected products:\nChrome\n\nDescription:\nRace condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106426 [0.0] Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chro"},{"CvssScore":"0.0","CveId":"CVE-2026-106423","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106423 [0.0] Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security"},{"CvssScore":"0.0","CveId":"CVE-2026-106421","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106421 [0.0] Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security s"},{"CvssScore":"0.0","CveId":"CVE-2026-106420","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106420 [0.0] Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chro"},{"CvssScore":"0.0","CveId":"CVE-2026-106419","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106419 [0.0] Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Ch"},{"CvssScore":"0.0","CveId":"CVE-2026-106417","Description":"Affected products:\nChrome\n\nDescription:\nInteger overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106417 [0.0] Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Ch"},{"CvssScore":"0.0","CveId":"CVE-2026-106416","Description":"Affected products:\nChrome\n\nDescription:\nCode injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106416 [0.0] Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. "},{"CvssScore":"0.0","CveId":"CVE-2026-106415","Description":"Affected products:\nChrome\n\nDescription:\nInformation leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106415 [0.0] Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severit"},{"CvssScore":"0.0","CveId":"CVE-2026-106414","Description":"Affected products:\nChrome\n\nDescription:\nImproper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106414 [0.0] Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary cod"},{"CvssScore":"0.0","CveId":"CVE-2026-106413","Description":"Affected products:\nChrome\n\nDescription:\nRace condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106413 [0.0] Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page."},{"CvssScore":"0.0","CveId":"CVE-2026-106412","Description":"Affected products:\nChrome\n\nDescription:\nRace condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106412 [0.0] Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to po"},{"CvssScore":"0.0","CveId":"CVE-2026-106411","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106411 [0.0] Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium securit"},{"CvssScore":"0.0","CveId":"CVE-2026-106410","Description":"Affected products:\nChrome\n\nDescription:\nMissing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106410 [0.0] Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted"},{"CvssScore":"0.0","CveId":"CVE-2026-106409","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106409 [0.0] Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute a"},{"CvssScore":"0.0","CveId":"CVE-2026-106406","Description":"Affected products:\nChrome\n\nDescription:\nMissing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106406 [0.0] Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML "},{"CvssScore":"0.0","CveId":"CVE-2026-106402","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106402 [0.0] Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome ex"},{"CvssScore":"0.0","CveId":"CVE-2026-106401","Description":"Affected products:\nChrome\n\nDescription:\nOut of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106401 [0.0] Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. "},{"CvssScore":"0.0","CveId":"CVE-2026-106400","Description":"Affected products:\nChrome\n\nDescription:\nClickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106400 [0.0] Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML pag"},{"CvssScore":"0.0","CveId":"CVE-2026-106393","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106393 [0.0] Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox"},{"CvssScore":"0.0","CveId":"CVE-2026-106391","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in WebShare in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106391 [0.0] Incorrect authorization in WebShare in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements "},{"CvssScore":"0.0","CveId":"CVE-2026-106390","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106390 [0.0] Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML "},{"CvssScore":"0.0","CveId":"CVE-2026-106383","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106383 [0.0] Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security"},{"CvssScore":"0.0","CveId":"CVE-2026-106382","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106382 [0.0] Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium se"},{"CvssScore":"0.0","CveId":"CVE-2026-106379","Description":"Affected products:\nChrome\n\nDescription:\nUninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106379 [0.0] Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity:"},{"CvssScore":"0.0","CveId":"CVE-2026-106378","Description":"Affected products:\nChrome\n\nDescription:\nPrivilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106378 [0.0] Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outs"},{"CvssScore":"0.0","CveId":"CVE-2026-106377","Description":"Affected products:\nChrome\n\nDescription:\nRace condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106377 [0.0] Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox v"},{"CvssScore":"0.0","CveId":"CVE-2026-106375","Description":"Affected products:\nChrome\n\nDescription:\nIncomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106375 [0.0] Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (C"},{"CvssScore":"0.0","CveId":"CVE-2026-106374","Description":"Affected products:\nChrome\n\nDescription:\nType confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106374 [0.0] Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security se"},{"CvssScore":"0.0","CveId":"CVE-2026-106373","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106373 [0.0] Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chr"},{"CvssScore":"0.0","CveId":"CVE-2026-106372","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106372 [0.0] Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page."},{"CvssScore":"0.0","CveId":"CVE-2026-106358","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106358 [0.0] Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium se"},{"CvssScore":"0.0","CveId":"CVE-2026-106357","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106357 [0.0] Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium securit"},{"CvssScore":"0.0","CveId":"CVE-2026-106356","Description":"Affected products:\nChrome\n\nDescription:\nClickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106356 [0.0] Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium securi"},{"CvssScore":"0.0","CveId":"CVE-2026-106354","Description":"Affected products:\nChrome\n\nDescription:\nImproper resource exposure in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106354 [0.0] Improper resource exposure in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security"},{"CvssScore":"0.0","CveId":"CVE-2026-106349","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106349 [0.0] Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security se"},{"CvssScore":"0.0","CveId":"CVE-2026-106347","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106347 [0.0] Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security"},{"CvssScore":"0.0","CveId":"CVE-2026-106346","Description":"Affected products:\nChrome\n\nDescription:\nImproper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106346 [0.0] Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTM"},{"CvssScore":"0.0","CveId":"CVE-2026-106345","Description":"Affected products:\nChrome\n\nDescription:\nUse of released resource in Session in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106345 [0.0] Use of released resource in Session in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted "},{"CvssScore":"0.0","CveId":"CVE-2026-106343","Description":"Affected products:\nChrome\n\nDescription:\nImproper state validation in Autofill AI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106343 [0.0] Improper state validation in Autofill AI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium s"},{"CvssScore":"0.0","CveId":"CVE-2026-106339","Description":"Affected products:\nChrome\n\nDescription:\nUse of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106339 [0.0] Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin dat"},{"CvssScore":"0.0","CveId":"CVE-2026-106338","Description":"Affected products:\nChrome\n\nDescription:\nUI misrepresentation in PictureInPicture in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106338 [0.0] UI misrepresentation in PictureInPicture in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium s"},{"CvssScore":"0.0","CveId":"CVE-2026-106335","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106335 [0.0] Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security"},{"CvssScore":"0.0","CveId":"CVE-2026-106333","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in Input in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106333 [0.0] Incorrect authorization in Input in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Ch"},{"CvssScore":"0.0","CveId":"CVE-2026-106332","Description":"Affected products:\nChrome\n\nDescription:\nInteger overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106332 [0.0] Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity"},{"CvssScore":"0.0","CveId":"CVE-2026-106330","Description":"Affected products:\nChrome\n\nDescription:\nInformation leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106330 [0.0] Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Me"},{"CvssScore":"0.0","CveId":"CVE-2026-106329","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106329 [0.0] Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outsid"},{"CvssScore":"0.0","CveId":"CVE-2026-106323","Description":"Affected products:\nChrome\n\nDescription:\nMissing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106323 [0.0] Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary"},{"CvssScore":"0.0","CveId":"CVE-2026-106321","Description":"Affected products:\nChrome\n\nDescription:\nInformation leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106321 [0.0] Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page."},{"CvssScore":"0.0","CveId":"CVE-2026-106320","Description":"Affected products:\nChrome\n\nDescription:\nUse of released resource in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106320 [0.0] Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML "},{"CvssScore":"0.0","CveId":"CVE-2026-106318","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106318 [0.0] Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security"},{"CvssScore":"0.0","CveId":"CVE-2026-106315","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106315 [0.0] Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium"},{"CvssScore":"0.0","CveId":"CVE-2026-106311","Description":"Affected products:\nChrome\n\nDescription:\nClickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106311 [0.0] Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (C"},{"CvssScore":"0.0","CveId":"CVE-2026-106298","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106298 [0.0] Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted "},{"CvssScore":"0.0","CveId":"CVE-2026-106295","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106295 [0.0] Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a"},{"CvssScore":"0.0","CveId":"CVE-2026-106293","Description":"Affected products:\nChrome\n\nDescription:\nType confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106293 [0.0] Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside t"},{"CvssScore":"0.0","CveId":"CVE-2026-106292","Description":"Affected products:\nChrome\n\nDescription:\nBuffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106292 [0.0] Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside "},{"CvssScore":"0.0","CveId":"CVE-2026-106291","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106291 [0.0] Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chrom"},{"CvssScore":"0.0","CveId":"CVE-2026-106283","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106283 [0.0] Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandb"},{"CvssScore":"0.0","CveId":"CVE-2026-106281","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106281 [0.0] Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chrom"},{"CvssScore":"0.0","CveId":"CVE-2026-106278","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106278 [0.0] Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafte"},{"CvssScore":"0.0","CveId":"CVE-2026-106270","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106270 [0.0] Incorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security sever"},{"CvssScore":"0.0","CveId":"CVE-2026-106269","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106269 [0.0] Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security s"},{"CvssScore":"0.0","CveId":"CVE-2026-106268","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106268 [0.0] Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium securit"},{"CvssScore":"0.0","CveId":"CVE-2026-106264","Description":"Affected products:\nChrome\n\nDescription:\nMissing authorization in Web Authentication (Passkeys \u0026 Security Keys) in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106264 [0.0] Missing authorization in Web Authentication (Passkeys \u0026 Security Keys) in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML p"},{"CvssScore":"0.0","CveId":"CVE-2026-106262","Description":"Affected products:\nChrome\n\nDescription:\nIncomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106262 [0.0] Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to "},{"CvssScore":"0.0","CveId":"CVE-2026-106257","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106257 [0.0] Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security "},{"CvssScore":"0.0","CveId":"CVE-2026-106255","Description":"Affected products:\nChrome\n\nDescription:\nRace condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106255 [0.0] Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium"},{"CvssScore":"0.0","CveId":"CVE-2026-106253","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106253 [0.0] Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium secu"},{"CvssScore":"0.0","CveId":"CVE-2026-106248","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106248 [0.0] Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium secur"},{"CvssScore":"0.0","CveId":"CVE-2026-106247","Description":"Affected products:\nChrome\n\nDescription:\nBuffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106247 [0.0] Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside "},{"CvssScore":"0.0","CveId":"CVE-2026-106246","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106246 [0.0] Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Me"},{"CvssScore":"0.0","CveId":"CVE-2026-106245","Description":"Affected products:\nChrome\n\nDescription:\nUninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106245 [0.0] Uninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity"},{"CvssScore":"0.0","CveId":"CVE-2026-106241","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106241 [0.0] Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary c"},{"CvssScore":"0.0","CveId":"CVE-2026-106240","Description":"Affected products:\nChrome\n\nDescription:\nType confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106240 [0.0] Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security se"},{"CvssScore":"0.0","CveId":"CVE-2026-106239","Description":"Affected products:\nChrome\n\nDescription:\nInteger overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106239 [0.0] Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted "},{"CvssScore":"0.0","CveId":"CVE-2026-106238","Description":"Affected products:\nChrome\n\nDescription:\nRace condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106238 [0.0] Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside t"},{"CvssScore":"0.0","CveId":"CVE-2026-106235","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106235 [0.0] Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium secur"},{"CvssScore":"0.0","CveId":"CVE-2026-106234","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106234 [0.0] Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbo"},{"CvssScore":"0.0","CveId":"CVE-2026-106233","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106233 [0.0] Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox"},{"CvssScore":"0.0","CveId":"CVE-2026-106228","Description":"Affected products:\nChrome\n\nDescription:\nConfused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106228 [0.0] Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code ou"},{"CvssScore":"0.0","CveId":"CVE-2026-106227","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106227 [0.0] Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security"},{"CvssScore":"0.0","CveId":"CVE-2026-106226","Description":"Affected products:\nChrome\n\nDescription:\nImproper input validation in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106226 [0.0] Improper input validation in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof address bar via a cra"},{"CvssScore":"0.0","CveId":"CVE-2026-106224","Description":"Affected products:\nChrome\n\nDescription:\nMissing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106224 [0.0] Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a "},{"CvssScore":"0.0","CveId":"CVE-2026-106222","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106222 [0.0] Incorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security "},{"CvssScore":"0.0","CveId":"CVE-2026-106211","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106211 [0.0] Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandb"},{"CvssScore":"0.0","CveId":"CVE-2026-106210","Description":"Affected products:\nChrome\n\nDescription:\nObservable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106210 [0.0] Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security "},{"CvssScore":"0.0","CveId":"CVE-2026-106207","Description":"Affected products:\nChrome\n\nDescription:\nRace condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106207 [0.0] Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security se"},{"CvssScore":"0.0","CveId":"CVE-2026-106204","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106204 [0.0] Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security se"},{"CvssScore":"0.0","CveId":"CVE-2026-106201","Description":"Affected products:\nChrome\n\nDescription:\nRace condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106201 [0.0] Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security se"},{"CvssScore":"0.0","CveId":"CVE-2026-106200","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106200 [0.0] Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security"},{"CvssScore":"0.0","CveId":"CVE-2026-106197","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106197 [0.0] Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secur"},{"CvssScore":"0.0","CveId":"CVE-2026-106194","Description":"Affected products:\nChrome\n\nDescription:\nMissing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106194 [0.0] Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineerin"},{"CvssScore":"0.0","CveId":"CVE-2026-106193","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106193 [0.0] Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium securit"},{"CvssScore":"0.0","CveId":"CVE-2026-106191","Description":"Affected products:\nChrome\n\nDescription:\nMissing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106191 [0.0] Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code ou"},{"CvssScore":"0.0","CveId":"CVE-2026-106190","Description":"Affected products:\nChrome\n\nDescription:\nUse after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106190 [0.0] Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security"},{"CvssScore":"0.0","CveId":"CVE-2026-106187","Description":"Affected products:\nChrome\n\nDescription:\nMissing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106187 [0.0] Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted"},{"CvssScore":"0.0","CveId":"CVE-2026-106186","Description":"Affected products:\nChrome\n\nDescription:\nUncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106186 [0.0] Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentially execute arbitrary code outsid"},{"CvssScore":"0.0","CveId":"CVE-2026-106184","Description":"Affected products:\nChrome\n\nDescription:\nUninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106184 [0.0] Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity"},{"CvssScore":"0.0","CveId":"CVE-2026-106180","Description":"Affected products:\nChrome\n\nDescription:\nObservable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-106180 [0.0] Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium s"},{"CvssScore":"MEDIUM 5.4","CveId":"CVE-2026-106033","Description":"Affected products:\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Hardened Images\n\nDescription:\nA DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application\u0027s redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser\u0027s location.href without verifying its format or scheme. The platform includes built-in URL validation functions designed to block malicious URI schemes (such as javascript: and data:) as well as off-site or protocol-relative redirects, this specific route bypasses those controls. Consequently, an attacker can craft a malicious link that, when accessed by an authenticated user, causes arbitrary JavaScript to execute within the context of the user\u0027s session.","Link":"https://access.redhat.com/security/cve/CVE-2026-106033","Title":"CVE-2026-106033 [MEDIUM 5.4] A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application\u0027s redirect route. Specifica"},{"CvssScore":"MEDIUM 6.5","CveId":"CVE-2026-103869","Description":"Affected products:\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Satellite 6\nRed Hat Satellite 6\n\nDescription:\nA flaw was found in pulp-ansible\u0027s bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.","Link":"https://access.redhat.com/security/cve/CVE-2026-103869","Title":"CVE-2026-103869 [MEDIUM 6.5] A flaw was found in pulp-ansible\u0027s bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download i"},{"CvssScore":"MEDIUM 6.5","CveId":"CVE-2026-103868","Description":"Affected products:\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Ansible Automation Platform 2\nRed Hat Satellite 6\nRed Hat Satellite 6\nRed Hat Update Infrastructure 4 for Cloud Providers\nRed Hat Update Infrastructure 4 for Cloud Providers\nRed Hat Update Infrastructure 5\nRed Hat Update Infrastructure 5\nRed Hat Update Infrastructure 5\n\nDescription:\nA flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry. Content stored in Pulp is not changed, and the service is not stopped.","Link":"https://access.redhat.com/security/cve/CVE-2026-103868","Title":"CVE-2026-103868 [MEDIUM 6.5] A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same w"},{"CvssScore":"0.0","CveId":"CVE-2026-102322","Description":"Affected products:\nChrome\n\nDescription:\nIncorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)","Link":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","Title":"CVE-2026-102322 [0.0] Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security s"},{"CvssScore":"0.0","CveId":"CVE-2025-64391","Description":"Affected products:\nAgent for Windows\n\nDescription:\nThis vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.","Link":"https://www.veeam.com/kb4902","Title":"CVE-2025-64391 [0.0] This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it."}],"Timestamp":"2026-10-07T17:34:20.059542+02:00","Youless":true,"Zabbix":true}