CVE-2026-106228

CVE-2026-106228 is a high-severity vulnerability with a CVSS 3.x base score of 8.3. The underlying weakness is classified as CWE-441.

Key facts

Description

Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Frequently asked questions

What is CVE-2026-106228?
Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
How severe is CVE-2026-106228?
CVE-2026-106228 has a CVSS 3.x base score of 8.3, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
Is CVE-2026-106228 being actively exploited?
It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
How do I fix CVE-2026-106228?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
When was CVE-2026-106228 published?
CVE-2026-106228 was published on 2026-10-06.

References

Other CWE-441 vulnerabilities

Browse all CWE-441 vulnerabilities →