CVE-2026-106243: Google Chrome

Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)

Affected products

  • Google Chrome: before 155.0.8059.39 (fixed in 155.0.8059.39)

Published 2026-10-06. Last modified 2026-10-07.