CVE-2026-106361

CVE-2026-106361 is a security vulnerability that is still awaiting full analysis and scoring. The underlying weakness is classified as CWE-684.

Key facts

Description

Incorrect provision of specified functionality in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

Frequently asked questions

What is CVE-2026-106361?
Incorrect provision of specified functionality in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
Is CVE-2026-106361 being actively exploited?
It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
How do I fix CVE-2026-106361?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
When was CVE-2026-106361 published?
CVE-2026-106361 was published on 2026-10-06.

References

Other CWE-684 vulnerabilities

Browse all CWE-684 vulnerabilities →