CVE-2026-106390
CVE-2026-106390 is a security vulnerability that is still awaiting full analysis and scoring. The underlying weakness is classified as CWE-684.
Key facts
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-684
- Published:
- Last modified:
Description
Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Frequently asked questions
- What is CVE-2026-106390?
- Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
- Is CVE-2026-106390 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-106390?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-106390 published?
- CVE-2026-106390 was published on 2026-10-06.
References
- https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html
- https://issues.chromium.org/issues/556213916
Other CWE-684 vulnerabilities
- CVE-2024-50357 — Critical (CVSS 9.8): FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in…
- CVE-2026-52735 — Critical (CVSS 9.3): ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because…
- CVE-2024-6425 — Critical (CVSS 9.1): Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote…
- CVE-2023-24845 — Critical (CVSS 9.1): A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM…
- CVE-2023-4258 — High (CVSS 8.6): In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be…
- CVE-2025-66384 — High (CVSS 8.2): app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity,…