Improper Input Validation in Google Chrome Extensions
CVE-2026-106331

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106331?

A vulnerability was identified in Google Chrome prior to version 155.0.8059.39, where improper input validation in Chrome extensions could allow remote attackers to exploit the system. By leveraging social engineering techniques, attackers may craft malicious Chrome extensions that could bypass web origin policy, gaining access to privileged pages within the browser. Users are encouraged to update their Chrome installations to mitigate potential threats.

Affected Version(s)

Chrome 155.0.8059.39

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.