CVE-2026-106390

CVE-2026-106390 is a security vulnerability that is still awaiting full analysis and scoring. The underlying weakness is classified as CWE-684.

Key facts

Description

Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

Frequently asked questions

What is CVE-2026-106390?
Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Is CVE-2026-106390 being actively exploited?
It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
How do I fix CVE-2026-106390?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
When was CVE-2026-106390 published?
CVE-2026-106390 was published on 2026-10-06.

References

Other CWE-684 vulnerabilities

Browse all CWE-684 vulnerabilities →