Web Origin Policy Bypass in Google Chrome
CVE-2026-106310

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106310?

A vulnerability in Google Chrome's FontAccess component prior to version 155.0.8059.39 allows attackers to bypass the web origin policy. By exploiting this flaw through a specially crafted HTML page, a remote attacker could leverage a compromised renderer process to access protected resources, leading to further security implications. This weakness underscores the importance of keeping software updated to mitigate potential threats.

Affected Version(s)

Chrome 155.0.8059.39

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.