Authorization Bypass Vulnerability in Google Chrome
CVE-2026-106259

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106259?

A vulnerability in Google Chrome's PermissionElement component allows remote attackers to bypass system access restrictions by exploiting an incorrectly implemented authorization mechanism. This can be achieved through a specially crafted HTML page, potentially compromising user security.

Affected Version(s)

Chrome 155.0.8059.39

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.