{"grype_matches":[{"artifact":{"id":"809ea4b423ef5f0e","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u4:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u4","language":"","licenses":["sha256:a07e99815cf1998f1dabbc21fe199460bfa09b85ead0d56b49a32cac3d1791b5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-3389","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"risk":3.66635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."}]},{"artifact":{"id":"3283c74353a6fd98","cpes":["cpe:2.3:a:xdg-utils:xdg-utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg-utils:xdg_utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg_utils:xdg-utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg_utils:xdg_utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg:xdg-utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg:xdg_utils:1.2.1-2:*:*:*:*:*:*:*"],"name":"xdg-utils","purl":"pkg:deb/debian/xdg-utils@1.2.1-2?arch=all&distro=debian-13.7","type":"deb","version":"1.2.1-2","language":"","licenses":["Expat"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xdg-utils/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/xdg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xdg-utils.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/xdg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xdg-utils.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/xdg-utils.list"},{"path":"/var/lib/dpkg/info/xdg-utils.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/xdg-utils.postinst"},{"path":"/var/lib/dpkg/info/xdg-utils.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/xdg-utils.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-27748","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"xdg-utils","version":"1.2.1-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2020-27748","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-27748","cwe":"CWE-201","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-27748","date":"2026-10-08","epss":0.01436,"percentile":0.72336}],"risk":0.8256999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-27748","description":"A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird."},"relatedVulnerabilities":[{"id":"CVE-2020-27748","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-27748","cwe":"CWE-201","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-27748","date":"2026-10-08","epss":0.01436,"percentile":0.72336}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1899769","https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/177"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27748","description":"A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66046","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"risk":0.60102,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."},"relatedVulnerabilities":[{"id":"CVE-2026-66046","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."}]},{"artifact":{"id":"a9126347f86cc263","cpes":["cpe:2.3:a:libcairo-gobject2:libcairo-gobject2:1.18.4-1\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-gobject2:libcairo_gobject2:1.18.4-1\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo-gobject2:1.18.4-1\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo_gobject2:1.18.4-1\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-gobject2:1.18.4-1\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_gobject2:1.18.4-1\\+b1:*:*:*:*:*:*:*"],"name":"libcairo-gobject2","purl":"pkg:deb/debian/libcairo-gobject2@1.18.4-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=cairo%401.18.4-1","type":"deb","version":"1.18.4-1+b1","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-gobject2/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libcairo-gobject2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo","version":"1.18.4-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-7475","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cairo","version":"1.18.4-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-7475","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"risk":0.5471999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2017-7475","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"urls":["http://seclists.org/oss-sec/2017/q2/151","https://bugs.freedesktop.org/show_bug.cgi?id=100763","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."}]},{"artifact":{"id":"ba412dc25febb8de","cpes":["cpe:2.3:a:libcairo2:libcairo2:1.18.4-1\\+b1:*:*:*:*:*:*:*"],"name":"libcairo2","purl":"pkg:deb/debian/libcairo2@1.18.4-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=cairo%401.18.4-1","type":"deb","version":"1.18.4-1+b1","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libcairo2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo","version":"1.18.4-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-7475","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cairo","version":"1.18.4-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-7475","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"risk":0.5471999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2017-7475","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"urls":["http://seclists.org/oss-sec/2017/q2/151","https://bugs.freedesktop.org/show_bug.cgi?id=100763","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-6988","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"risk":0.5172,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."},"relatedVulnerabilities":[{"id":"CVE-2019-6988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"urls":["http://www.securityfocus.com/bid/106785","https://github.com/uclouvain/openjpeg/issues/1178"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."}]},{"artifact":{"id":"3283c74353a6fd98","cpes":["cpe:2.3:a:xdg-utils:xdg-utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg-utils:xdg_utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg_utils:xdg-utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg_utils:xdg_utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg:xdg-utils:1.2.1-2:*:*:*:*:*:*:*","cpe:2.3:a:xdg:xdg_utils:1.2.1-2:*:*:*:*:*:*:*"],"name":"xdg-utils","purl":"pkg:deb/debian/xdg-utils@1.2.1-2?arch=all&distro=debian-13.7","type":"deb","version":"1.2.1-2","language":"","licenses":["Expat"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xdg-utils/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/xdg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xdg-utils.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/xdg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xdg-utils.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/xdg-utils.list"},{"path":"/var/lib/dpkg/info/xdg-utils.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/xdg-utils.postinst"},{"path":"/var/lib/dpkg/info/xdg-utils.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/xdg-utils.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-4055","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"xdg-utils","version":"1.2.1-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2022-4055","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4055","cwe":"CWE-146","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4055","date":"2026-10-08","epss":0.00678,"percentile":0.50827}],"risk":0.50511,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-4055","description":"When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked."},"relatedVulnerabilities":[{"id":"CVE-2022-4055","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4055","cwe":"CWE-146","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4055","date":"2026-10-08","epss":0.00678,"percentile":0.50827}],"urls":["https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/205#note_1494267"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4055","description":"When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked."}]},{"artifact":{"id":"e2c0cfe2f366c89d","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u3:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u3?arch=amd64&distro=debian-13.7&upstream=tiff","type":"deb","version":"4.7.0-3+deb13u3","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-52490","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tiff","version":"4.7.0-3+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-52490","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"risk":0.47940000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"},"relatedVulnerabilities":[{"id":"CVE-2026-52490","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"urls":["https://gist.github.com/okyfh/122c2d72e991a78c8af80a3af3be8671","https://gitlab.com/libtiff/libtiff/-/work_items/846"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"}]},{"artifact":{"id":"1ed310f43f3fc66d","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106358","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106358","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"risk":0.40734,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106358","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160164"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106358","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106358","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"risk":0.40734,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106358","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160164"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106358","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106358","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"risk":0.40734,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106358","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160164"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106358","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106358","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"risk":0.40734,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106358","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160164"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106358","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106358","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"risk":0.40734,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106358","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106358","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106358","date":"2026-10-08","epss":0.00438,"percentile":0.3607}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160164"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106358","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"bc1992b0286c920a","cpes":["cpe:2.3:a:libsndfile1:libsndfile1:1.2.2-2\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsndfile1","purl":"pkg:deb/debian/libsndfile1@1.2.2-2%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=libsndfile","type":"deb","version":"1.2.2-2+deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-clause","FSFAP","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","NTP","gsm","sun"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsndfile1/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libsndfile1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsndfile1:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libsndfile1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libsndfile"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-37555","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libsndfile","version":"1.2.2-2+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-37555","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-37555","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-37555","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-37555","date":"2026-10-08","epss":0.00504,"percentile":0.41183}],"risk":0.39564,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-37555","description":"An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065."},"relatedVulnerabilities":[{"id":"CVE-2026-37555","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-37555","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-37555","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-37555","date":"2026-10-08","epss":0.00504,"percentile":0.41183}],"urls":["https://gist.github.com/sgInnora/a5f5c19e4bf6f4fb74fab7b0ef2bfcc1","https://github.com/libsndfile/libsndfile/commit/9a829113c88a51e57c1e46473e90609e4b7df151","https://github.com/libsndfile/libsndfile/issues/833","https://access.redhat.com/errata/RHSA-2026:19559","https://access.redhat.com/errata/RHSA-2026:19560","https://access.redhat.com/errata/RHSA-2026:19610","https://access.redhat.com/errata/RHSA-2026:23221","https://access.redhat.com/errata/RHSA-2026:23222","https://access.redhat.com/errata/RHSA-2026:23223","https://access.redhat.com/errata/RHSA-2026:25092","https://access.redhat.com/errata/RHSA-2026:25197","https://access.redhat.com/errata/RHSA-2026:25198","https://access.redhat.com/errata/RHSA-2026:25227","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/security/cve/CVE-2026-37555","https://bugzilla.redhat.com/show_bug.cgi?id=2463856","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-37555.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-37555","description":"An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106227","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106227","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106227","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/561891645"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106239","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106239","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106239","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/546630009"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106227","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106227","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106227","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/561891645"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106239","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106239","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106239","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/546630009"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106227","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106227","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106227","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/561891645"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106239","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106239","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106239","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/546630009"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106227","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106227","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106227","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/561891645"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106239","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106239","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106239","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/546630009"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106227","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106227","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106227","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106227","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106227","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/561891645"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106227","description":"Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106239","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106239","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"risk":0.39338999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106239","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106239","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106239","date":"2026-10-08","epss":0.00423,"percentile":0.34646}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/546630009"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106239","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106211","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"risk":0.38037,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106211","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562002095"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106211","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"risk":0.38037,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106211","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562002095"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106211","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"risk":0.38037,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106211","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562002095"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106211","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"risk":0.38037,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106211","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562002095"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106211","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"risk":0.38037,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106211","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106211","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106211","date":"2026-10-08","epss":0.00409,"percentile":0.33041}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562002095"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106211","description":"Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106357","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106357","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"risk":0.377345,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106357","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106357","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106357","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"risk":0.377345,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106357","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106357","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106357","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"risk":0.377345,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106357","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106357","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106357","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"risk":0.377345,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106357","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106357","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106357","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"risk":0.377345,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106357","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106357","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106357","date":"2026-10-08","epss":0.00463,"percentile":0.3815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567160162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106357","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103631","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103631","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"risk":0.3749,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103631","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/567088927"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103631","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103631","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"risk":0.3749,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103631","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/567088927"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103631","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103631","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"risk":0.3749,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103631","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/567088927"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103631","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103631","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"risk":0.3749,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103631","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/567088927"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103631","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103631","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"risk":0.3749,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103631","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103631","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103631","date":"2026-10-08","epss":0.0046,"percentile":0.3784}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/567088927"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103631","description":"Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106375","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106375","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106375","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536507840"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106375","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106375","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106375","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536507840"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106375","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106375","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106375","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536507840"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106375","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106375","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106375","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536507840"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106375","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106375","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106375","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106375","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106375","date":"2026-10-08","epss":0.00402,"percentile":0.32345}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536507840"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106375","description":"Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106197","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106197","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106197","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560238696"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106197","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106197","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106197","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560238696"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106197","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106197","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106197","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560238696"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106197","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106197","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106197","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560238696"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106197","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106197","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"risk":0.37385999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106197","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106197","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106197","date":"2026-10-08","epss":0.00402,"percentile":0.3233}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560238696"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106197","description":"Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102322","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102322","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"risk":0.37013999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-102322","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/527023137"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102322","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102322","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"risk":0.37013999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-102322","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/527023137"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102322","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102322","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"risk":0.37013999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-102322","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/527023137"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102322","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102322","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"risk":0.37013999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-102322","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/527023137"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102322","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102322","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"risk":0.37013999999999997,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-102322","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102322","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-102322","date":"2026-10-08","epss":0.00398,"percentile":0.3185}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/527023137"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102322","description":"Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106382","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"risk":0.36827999999999994,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106382","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534994449"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106382","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"risk":0.36827999999999994,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106382","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534994449"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106382","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"risk":0.36827999999999994,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106382","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534994449"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106382","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"risk":0.36827999999999994,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106382","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534994449"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106382","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"risk":0.36827999999999994,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106382","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106382","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106382","date":"2026-10-08","epss":0.00396,"percentile":0.31684}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534994449"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106382","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106240","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106240","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"risk":0.36186000000000007,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106240","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567177599"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106240","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106240","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"risk":0.36186000000000007,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106240","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567177599"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106240","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106240","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"risk":0.36186000000000007,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106240","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567177599"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106240","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106240","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"risk":0.36186000000000007,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106240","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567177599"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106240","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106240","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"risk":0.36186000000000007,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106240","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106240","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106240","date":"2026-10-08","epss":0.00444,"percentile":0.36557}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567177599"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106240","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-74860","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-74860","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"risk":0.3488,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."},"relatedVulnerabilities":[{"id":"CVE-2026-74860","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"urls":["https://access.redhat.com/errata/RHSA-2026:64463","https://access.redhat.com/errata/RHSA-2026:71585","https://access.redhat.com/errata/RHSA-2026:71586","https://access.redhat.com/errata/RHSA-2026:71641","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/security/cve/CVE-2026-74860","https://bugzilla.redhat.com/show_bug.cgi?id=2529697"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103628","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"risk":0.3441,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-103628","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/549995090"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103628","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"risk":0.3441,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-103628","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/549995090"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103628","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"risk":0.3441,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-103628","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/549995090"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103628","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"risk":0.3441,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-103628","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/549995090"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103628","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"risk":0.3441,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-103628","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103628","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103628","date":"2026-10-08","epss":0.0037,"percentile":0.28863}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/549995090"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103628","description":"Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.34299,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.34299,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.34299,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"212a71fa16031fdf","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"7402a3d31bb024db","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"3f9378db54aaac9e","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"e96cb50e09a471e0","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-39329","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"risk":0.33809999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2023-39329","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39329","https://bugzilla.redhat.com/show_bug.cgi?id=2295816","https://github.com/uclouvain/openjpeg/issues/1474"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."}]},{"artifact":{"id":"1ed310f43f3fc66d","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6653","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6653","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"risk":0.33370000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."},"relatedVulnerabilities":[{"id":"CVE-2026-6653","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"urls":["https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106329","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106329","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562043997"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106329","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106329","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562043997"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106329","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106329","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562043997"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106329","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106329","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562043997"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106329","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106329","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106329","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106329","date":"2026-10-08","epss":0.00355,"percentile":0.27211}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/562043997"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106329","description":"Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106372","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106372","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106372","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557288890"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106372","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106372","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106372","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557288890"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106372","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106372","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106372","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557288890"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106372","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106372","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106372","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557288890"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106372","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106372","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"risk":0.33015,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106372","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106372","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106372","date":"2026-10-08","epss":0.00355,"percentile":0.2721}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557288890"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106372","description":"Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.32642999999999994,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106281","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106281","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554992296"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106298","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106298","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/555932520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106401","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106401","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106401","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553129739"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106419","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106419","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106419","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/550379413"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106281","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106281","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554992296"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106298","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106298","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/555932520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106401","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106401","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106401","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553129739"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106419","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106419","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106419","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/550379413"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106281","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106281","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554992296"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106298","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106298","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/555932520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106401","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106401","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106401","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553129739"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106419","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106419","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106419","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/550379413"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106281","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106281","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554992296"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106298","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106298","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/555932520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106401","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106401","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106401","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553129739"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106419","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106419","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106419","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/550379413"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106281","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106281","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106281","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106281","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554992296"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106281","description":"Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106298","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106298","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106298","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106298","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/555932520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106298","description":"Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106401","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106401","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106401","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106401","cwe":"CWE-787","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106401","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553129739"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106401","description":"Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106419","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106419","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106419","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106419","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106419","date":"2026-10-08","epss":0.00338,"percentile":0.25188}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/550379413"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106419","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106414","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106414","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106414","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/504223609"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106414","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106414","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106414","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/504223609"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106414","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106414","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106414","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/504223609"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106414","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106414","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106414","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/504223609"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106414","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106414","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106414","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106414","cwe":"CWE-20","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106414","date":"2026-10-08","epss":0.00338,"percentile":0.25187}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/504223609"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106414","description":"Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106417","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106417","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106417","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536471438"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106417","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106417","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106417","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536471438"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106417","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106417","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106417","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536471438"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106417","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106417","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106417","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536471438"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106417","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106417","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"risk":0.31433999999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106417","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106417","cwe":"CWE-190","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106417","date":"2026-10-08","epss":0.00338,"percentile":0.25144}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/536471438"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106417","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106235","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106235","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106235","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565612897"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106268","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106268","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106268","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742177"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106235","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106235","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106235","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565612897"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106268","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106268","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106268","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742177"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106235","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106235","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106235","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565612897"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106268","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106268","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106268","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742177"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106235","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106235","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106235","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565612897"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106268","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106268","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106268","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742177"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106235","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106235","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106235","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106235","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106235","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565612897"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106235","description":"Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106268","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106268","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"risk":0.31214500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106268","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106268","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106268","date":"2026-10-08","epss":0.00383,"percentile":0.30236}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742177"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106268","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"bc1992b0286c920a","cpes":["cpe:2.3:a:libsndfile1:libsndfile1:1.2.2-2\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsndfile1","purl":"pkg:deb/debian/libsndfile1@1.2.2-2%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=libsndfile","type":"deb","version":"1.2.2-2+deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-clause","FSFAP","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","NTP","gsm","sun"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsndfile1/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libsndfile1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsndfile1:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libsndfile1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libsndfile"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-50613","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libsndfile","version":"1.2.2-2+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-50613","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-50613","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-50613","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-50613","date":"2026-10-08","epss":0.0054,"percentile":0.43664}],"risk":0.3105,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50613","description":"libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close."},"relatedVulnerabilities":[{"id":"CVE-2024-50613","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-50613","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-50613","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-50613","date":"2026-10-08","epss":0.0054,"percentile":0.43664}],"urls":["https://github.com/libsndfile/libsndfile/issues/1034"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50613","description":"libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106241","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106241","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106241","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501729675"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106323","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106323","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106323","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553114676"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106241","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106241","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106241","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501729675"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106323","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106323","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106323","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553114676"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106241","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106241","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106241","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501729675"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106323","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106323","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106323","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553114676"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106241","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106241","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106241","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501729675"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106323","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106323","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106323","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553114676"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106241","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106241","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106241","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106241","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106241","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501729675"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106241","description":"Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106323","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106323","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"risk":0.30318,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106323","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106323","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106323","date":"2026-10-08","epss":0.00326,"percentile":0.23632}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553114676"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106323","description":"Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103626","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103626","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103626","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/553114097"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103626","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103626","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103626","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/553114097"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103626","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103626","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103626","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/553114097"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103626","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103626","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103626","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/553114097"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103626","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103626","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103626","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103626","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103626","date":"2026-10-08","epss":0.00325,"percentile":0.23579}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/553114097"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103626","description":"Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103630","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103630","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103630","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/557323166"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103630","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103630","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103630","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/557323166"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103630","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103630","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103630","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/557323166"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103630","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103630","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103630","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/557323166"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103630","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103630","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"risk":0.30224999999999996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103630","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103630","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103630","date":"2026-10-08","epss":0.00325,"percentile":0.23513}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/557323166"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103630","description":"Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"1f32975dfd37be95","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/debian/libpam-modules@1.7.0-5?arch=amd64&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"cb7fdbb7b6a04bdc","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/debian/libpam-modules-bin@1.7.0-5?arch=amd64&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"eb5873c5c35e21b8","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/debian/libpam-runtime@1.7.0-5?arch=all&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"1c6c7728b37b94de","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/debian/libpam0g@1.7.0-5?arch=amd64&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106374","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"risk":0.294215,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106374","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/552832446"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106374","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"risk":0.294215,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106374","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/552832446"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106374","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"risk":0.294215,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106374","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/552832446"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106374","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"risk":0.294215,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106374","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/552832446"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106374","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"risk":0.294215,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106374","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106374","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106374","date":"2026-10-08","epss":0.00361,"percentile":0.27782}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/552832446"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106374","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106233","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106233","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"risk":0.29309,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106233","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565797213"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106233","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106233","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"risk":0.29309,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106233","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565797213"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106233","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106233","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"risk":0.29309,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106233","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565797213"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106233","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106233","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"risk":0.29309,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106233","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565797213"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106233","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106233","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"risk":0.29309,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106233","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106233","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106233","date":"2026-10-08","epss":0.00371,"percentile":0.28913}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565797213"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106233","description":"Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"bc1992b0286c920a","cpes":["cpe:2.3:a:libsndfile1:libsndfile1:1.2.2-2\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsndfile1","purl":"pkg:deb/debian/libsndfile1@1.2.2-2%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=libsndfile","type":"deb","version":"1.2.2-2+deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-clause","FSFAP","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","NTP","gsm","sun"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsndfile1/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libsndfile1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsndfile1:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libsndfile1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libsndfile"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88372","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libsndfile","version":"1.2.2-2+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-88372","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88372","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-88372","date":"2026-10-08","epss":0.0039,"percentile":0.30956}],"risk":0.2925,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-88372","description":"libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files."},"relatedVulnerabilities":[{"id":"CVE-2026-88372","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88372","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-88372","date":"2026-10-08","epss":0.0039,"percentile":0.30956}],"urls":["https://github.com/libsndfile/libsndfile/issues/1151"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88372","description":"libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"5886e793c6b08095","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"e9141be499a1730f","cpes":["cpe:2.3:a:locales:locales:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106234","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106234","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"risk":0.29016,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106234","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/564085088"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106234","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106234","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"risk":0.29016,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106234","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/564085088"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106234","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106234","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"risk":0.29016,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106234","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/564085088"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106234","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106234","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"risk":0.29016,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106234","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/564085088"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106234","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106234","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"risk":0.29016,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106234","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106234","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106234","date":"2026-10-08","epss":0.00312,"percentile":0.22117}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/564085088"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106234","description":"Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)"}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52615","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"risk":0.28891500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."},"relatedVulnerabilities":[{"id":"CVE-2024-52615","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52615","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"risk":0.28891500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."},"relatedVulnerabilities":[{"id":"CVE-2024-52615","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52615","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"risk":0.28891500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."},"relatedVulnerabilities":[{"id":"CVE-2024-52615","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"5886e793c6b08095","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"e9141be499a1730f","cpes":["cpe:2.3:a:locales:locales:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106228","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"risk":0.28203,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106228","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517689673"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106228","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"risk":0.28203,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106228","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517689673"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106228","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"risk":0.28203,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106228","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517689673"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106228","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"risk":0.28203,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106228","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517689673"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106228","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"risk":0.28203,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106228","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106228","cwe":"CWE-441","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106228","date":"2026-10-08","epss":0.00357,"percentile":0.27398}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517689673"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106228","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"0e36aed774c3fe69","cpes":["cpe:2.3:a:libminizip1t64:libminizip1t64:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"libminizip1t64","purl":"pkg:deb/debian/libminizip1t64@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libminizip1t64/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libminizip1t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libminizip1t64:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libminizip1t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"8a1ec6d9372df578","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106190","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"risk":0.281175,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566824998"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106190","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"risk":0.281175,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566824998"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106190","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"risk":0.281175,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566824998"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106190","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"risk":0.281175,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566824998"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106190","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"risk":0.281175,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106190","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106190","date":"2026-10-08","epss":0.00345,"percentile":0.2591}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566824998"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106190","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"e2c0cfe2f366c89d","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u3:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u3?arch=amd64&distro=debian-13.7&upstream=tiff","type":"deb","version":"4.7.0-3+deb13u3","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-16232","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tiff","version":"4.7.0-3+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-16232","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"risk":0.2792,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"},"relatedVulnerabilities":[{"id":"CVE-2017-16232","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00036.html","http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00041.html","http://packetstormsecurity.com/files/150896/LibTIFF-4.0.8-Memory-Leak.html","http://seclists.org/fulldisclosure/2018/Dec/32","http://seclists.org/fulldisclosure/2018/Dec/47","http://www.openwall.com/lists/oss-security/2017/11/01/11","http://www.openwall.com/lists/oss-security/2017/11/01/3","http://www.openwall.com/lists/oss-security/2017/11/01/7","http://www.openwall.com/lists/oss-security/2017/11/01/8","http://www.securityfocus.com/bid/101696"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106194","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106194","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"risk":0.27808000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106194","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/498739277"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106194","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106194","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"risk":0.27808000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106194","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/498739277"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106194","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106194","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"risk":0.27808000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106194","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/498739277"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106194","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106194","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"risk":0.27808000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106194","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/498739277"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106194","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106194","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"risk":0.27808000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106194","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106194","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106194","date":"2026-10-08","epss":0.00352,"percentile":0.26795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/498739277"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106194","description":"Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8a928cc6733b8d4c","cpes":["cpe:2.3:a:gcc-14-base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-base","purl":"pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/gcc-14-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"4aef59838e786012","cpes":["cpe:2.3:a:libatomic1:libatomic1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libatomic1","purl":"pkg:deb/debian/libatomic1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libatomic1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"2338ed612a82adf3","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"7dc961cf921ecd08","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106193","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106193","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106193","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557729858"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106200","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106200","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106200","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/568422505"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106193","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106193","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106193","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557729858"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106200","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106200","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106200","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/568422505"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106193","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106193","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106193","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557729858"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106200","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106200","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106200","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/568422505"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106193","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106193","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106193","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557729858"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106200","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106200","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106200","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/568422505"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106193","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106193","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106193","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106193","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106193","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/557729858"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106193","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106200","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106200","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"risk":0.2730250000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106200","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106200","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106200","date":"2026-10-08","epss":0.00335,"percentile":0.24885}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/568422505"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106200","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-61915","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-61915","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61915","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-61915","cwe":"CWE-129","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-61915","date":"2026-10-08","epss":0.00462,"percentile":0.3811}],"risk":0.27026999999999995,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61915","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15."},"relatedVulnerabilities":[{"id":"CVE-2025-61915","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6,"impactScore":4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61915","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-61915","cwe":"CWE-129","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-61915","date":"2026-10-08","epss":0.00462,"percentile":0.3811}],"urls":["https://github.com/OpenPrinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","https://github.com/OpenPrinting/cups/releases/tag/v2.4.15","https://github.com/OpenPrinting/cups/security/advisories/GHSA-hxm8-vfpq-jrfc","http://www.openwall.com/lists/oss-security/2025/11/27/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61915","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106335","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106335","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106335","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502105238"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106373","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106373","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106373","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/523699645"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106383","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106383","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567447106"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106335","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106335","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106335","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502105238"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106373","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106373","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106373","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/523699645"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106383","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106383","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567447106"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106335","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106335","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106335","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502105238"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106373","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106373","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106373","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/523699645"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106383","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106383","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567447106"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106335","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106335","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106335","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502105238"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106373","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106373","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106373","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/523699645"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106383","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106383","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567447106"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106335","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106335","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106335","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106335","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106335","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502105238"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106335","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106373","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106373","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106373","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106373","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106373","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/523699645"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106373","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106383","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106383","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"risk":0.26976500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106383","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106383","date":"2026-10-08","epss":0.00331,"percentile":0.24142}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567447106"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106383","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106191","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106191","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"risk":0.26307,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502282293"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106191","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106191","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"risk":0.26307,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502282293"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106191","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106191","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"risk":0.26307,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502282293"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106191","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106191","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"risk":0.26307,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502282293"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106191","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106191","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"risk":0.26307,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106191","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106191","date":"2026-10-08","epss":0.00333,"percentile":0.24525}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/502282293"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106191","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524587778"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524587778"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524587778"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524587778"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106292","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106292","date":"2026-10-08","epss":0.00332,"percentile":0.24314}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524587778"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106292","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106247","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106247","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106247","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524435922"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106247","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106247","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106247","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524435922"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106247","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106247","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106247","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524435922"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106247","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106247","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106247","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524435922"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106247","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106247","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"risk":0.26228,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106247","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106247","cwe":"CWE-122","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106247","date":"2026-10-08","epss":0.00332,"percentile":0.24313}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/524435922"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106247","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106341","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106341","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"risk":0.259985,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106341","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/558539954"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106341","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106341","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"risk":0.259985,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106341","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/558539954"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106341","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106341","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"risk":0.259985,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106341","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/558539954"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106341","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106341","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"risk":0.259985,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106341","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/558539954"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106341","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106341","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"risk":0.259985,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106341","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106341","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106341","date":"2026-10-08","epss":0.00319,"percentile":0.22847}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/558539954"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106341","description":"Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103625","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103625","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103625","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/559893859"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103625","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103625","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103625","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/559893859"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103625","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103625","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103625","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/559893859"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103625","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103625","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103625","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/559893859"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103625","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103625","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103625","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103625","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103625","date":"2026-10-08","epss":0.00317,"percentile":0.22612}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/559893859"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103625","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106220","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106220","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106220","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534843648"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106220","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106220","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106220","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534843648"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106220","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106220","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106220","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534843648"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106220","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106220","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106220","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534843648"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106220","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106220","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"risk":0.25835500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106220","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106220","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106220","date":"2026-10-08","epss":0.00317,"percentile":0.22593}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/534843648"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106220","description":"Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39327","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-39327","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39327","date":"2026-10-08","epss":0.00555,"percentile":0.44547}],"risk":0.258075,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39327","description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal."},"relatedVulnerabilities":[{"id":"CVE-2023-39327","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39327","date":"2026-10-08","epss":0.00555,"percentile":0.44547}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39327","https://bugzilla.redhat.com/show_bug.cgi?id=2295812","https://github.com/uclouvain/openjpeg/issues/1472"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39327","description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"5886e793c6b08095","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"e9141be499a1730f","cpes":["cpe:2.3:a:locales:locales:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106293","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106293","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106293","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/547343108"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106293","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106293","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106293","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/547343108"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106293","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106293","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106293","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/547343108"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106293","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106293","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106293","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/547343108"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106293","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106293","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106293","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106293","cwe":"CWE-843","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106293","date":"2026-10-08","epss":0.00323,"percentile":0.23323}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/547343108"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106293","description":"Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106378","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106378","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106378","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/507596239"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106378","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106378","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106378","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/507596239"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106378","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106378","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106378","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/507596239"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106378","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106378","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106378","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/507596239"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106378","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106378","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"risk":0.25517,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106378","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106378","cwe":"CWE-250","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106378","date":"2026-10-08","epss":0.00323,"percentile":0.23316}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/507596239"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106378","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106347","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106347","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"risk":0.255095,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106347","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567936270"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106347","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106347","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"risk":0.255095,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106347","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567936270"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106347","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106347","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"risk":0.255095,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106347","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567936270"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106347","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106347","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"risk":0.255095,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106347","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567936270"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106347","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106347","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"risk":0.255095,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"},"relatedVulnerabilities":[{"id":"CVE-2026-106347","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106347","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106347","date":"2026-10-08","epss":0.00313,"percentile":0.22257}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567936270"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106347","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106352","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106352","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"risk":0.25346500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106352","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553139506"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106352","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106352","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"risk":0.25346500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106352","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553139506"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106352","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106352","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"risk":0.25346500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106352","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553139506"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106352","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106352","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"risk":0.25346500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106352","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553139506"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106352","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106352","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"risk":0.25346500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106352","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106352","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106352","date":"2026-10-08","epss":0.00311,"percentile":0.21993}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553139506"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106352","description":"Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106204","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"risk":0.251835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106204","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567910530"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106204","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"risk":0.251835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106204","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567910530"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106204","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"risk":0.251835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106204","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567910530"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106204","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"risk":0.251835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106204","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567910530"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106204","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"risk":0.251835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106204","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106204","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106204","date":"2026-10-08","epss":0.00309,"percentile":0.21795}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567910530"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106204","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)"}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34980","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34980","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34980","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34980","date":"2026-10-08","epss":0.00335,"percentile":0.24876}],"risk":0.25125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34980","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches."},"relatedVulnerabilities":[{"id":"CVE-2026-34980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34980","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34980","date":"2026-10-08","epss":0.00335,"percentile":0.24876}],"urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34980","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106203","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106203","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106203","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553394296"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106203","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106203","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106203","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553394296"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106203","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106203","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106203","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553394296"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106203","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106203","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106203","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553394296"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106203","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106203","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106203","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106203","cwe":"CWE-459","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106203","date":"2026-10-08","epss":0.00305,"percentile":0.21349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553394296"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106203","description":"Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106225","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106225","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106225","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501805355"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106225","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106225","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106225","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501805355"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106225","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106225","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106225","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501805355"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106225","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106225","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106225","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501805355"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106225","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106225","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"risk":0.24857500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106225","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106225","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106225","date":"2026-10-08","epss":0.00305,"percentile":0.21327}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/501805355"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106225","description":"Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103622","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103622","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103622","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742179"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103623","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103623","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103623","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742180"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106257","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106257","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565674529"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106421","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106421","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567873463"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103622","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103622","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103622","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742179"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103623","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103623","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103623","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742180"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106257","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106257","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565674529"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106421","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106421","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567873463"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103622","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103622","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103622","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742179"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103623","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103623","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103623","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742180"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106257","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106257","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565674529"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106421","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106421","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567873463"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103622","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103622","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103622","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742179"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103623","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103623","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103623","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742180"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106257","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106257","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565674529"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106421","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106421","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567873463"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103622","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103622","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103622","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103622","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103622","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742179"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103622","description":"Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103623","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103623","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103623","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103623","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103623","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/565742180"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103623","description":"Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106257","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106257","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106257","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106257","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565674529"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106257","description":"Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106421","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106421","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106421","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106421","date":"2026-10-08","epss":0.00303,"percentile":0.21132}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567873463"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106421","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106269","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106269","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106269","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742178"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106423","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106423","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106423","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566347711"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106269","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106269","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106269","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742178"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106423","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106423","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106423","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566347711"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106269","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106269","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106269","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742178"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106423","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106423","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106423","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566347711"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106269","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106269","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106269","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742178"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106423","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106423","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106423","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566347711"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106269","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106269","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106269","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106269","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106269","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565742178"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106269","description":"Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106423","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106423","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106423","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106423","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106423","date":"2026-10-08","epss":0.00303,"percentile":0.21131}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566347711"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106423","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106248","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106248","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106248","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/563673584"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106283","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106283","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499468981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106315","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106315","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106315","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/497652727"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106318","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106318","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106318","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566111249"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106248","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106248","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106248","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/563673584"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106283","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106283","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499468981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106315","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106315","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106315","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/497652727"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106318","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106318","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106318","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566111249"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106248","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106248","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106248","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/563673584"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106283","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106283","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499468981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106315","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106315","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106315","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/497652727"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106318","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106318","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106318","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566111249"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106248","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106248","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106248","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/563673584"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106283","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106283","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499468981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106315","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106315","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106315","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/497652727"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106318","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106318","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106318","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566111249"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106248","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106248","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106248","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106248","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106248","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/563673584"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106248","description":"Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106283","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106283","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106283","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106283","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499468981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106283","description":"Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106315","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106315","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106315","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106315","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106315","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/497652727"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106315","description":"Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106318","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106318","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106318","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106318","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106318","date":"2026-10-08","epss":0.00303,"percentile":0.2113}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566111249"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106318","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106252","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106252","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106252","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/513446410"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106252","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106252","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106252","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/513446410"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106252","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106252","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106252","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/513446410"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106252","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106252","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106252","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/513446410"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106252","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106252","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106252","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106252","cwe":"CWE-697","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106252","date":"2026-10-08","epss":0.00303,"percentile":0.21129}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/513446410"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106252","description":"Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106278","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106278","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106278","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565774991"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106291","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106291","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106291","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499571442"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106411","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106411","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566136674"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106278","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106278","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106278","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565774991"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106291","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106291","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106291","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499571442"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106411","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106411","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566136674"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106278","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106278","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106278","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565774991"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106291","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106291","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106291","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499571442"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106411","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106411","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566136674"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106278","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106278","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106278","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565774991"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106291","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106291","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106291","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499571442"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106411","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106411","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566136674"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106278","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106278","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106278","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106278","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106278","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/565774991"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106278","description":"Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106291","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106291","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106291","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106291","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106291","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/499571442"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106291","description":"Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106411","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"risk":0.24694500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106411","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106411","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106411","date":"2026-10-08","epss":0.00303,"percentile":0.21096}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566136674"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106411","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34978","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34978","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34978","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34978","date":"2026-10-08","epss":0.0042,"percentile":0.34261}],"risk":0.24149999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34978","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches."},"relatedVulnerabilities":[{"id":"CVE-2026-34978","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34978","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34978","date":"2026-10-08","epss":0.0042,"percentile":0.34261}],"urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34978","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106212","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106212","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540072162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106387","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106387","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/518096516"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106212","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106212","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540072162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106387","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106387","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/518096516"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106212","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106212","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540072162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106387","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106387","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/518096516"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106212","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106212","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540072162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106387","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106387","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/518096516"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106212","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106212","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106212","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106212","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540072162"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106212","description":"Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106387","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"risk":0.23961,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106387","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106387","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106387","date":"2026-10-08","epss":0.00294,"percentile":0.20218}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/518096516"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106387","description":"Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106221","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106221","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"risk":0.23937000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540049672"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106221","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106221","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"risk":0.23937000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540049672"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106221","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106221","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"risk":0.23937000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540049672"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106221","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106221","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"risk":0.23937000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540049672"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106221","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106221","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"risk":0.23937000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106221","cwe":"CWE-441","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106221","date":"2026-10-08","epss":0.00303,"percentile":0.21175}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/540049672"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106221","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106346","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106346","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106346","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566404364"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106346","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106346","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106346","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566404364"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106346","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106346","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106346","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566404364"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106346","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106346","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106346","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566404364"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106346","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106346","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106346","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106346","cwe":"CWE-754","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106346","date":"2026-10-08","epss":0.00292,"percentile":0.20007}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/566404364"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106346","description":"Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106207","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106207","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106207","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554619028"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106207","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106207","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106207","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554619028"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106207","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106207","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106207","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554619028"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106207","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106207","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106207","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554619028"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106207","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106207","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106207","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106207","cwe":"CWE-367","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106207","date":"2026-10-08","epss":0.00292,"percentile":0.19983}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/554619028"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106207","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106349","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106349","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106349","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567538973"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106349","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106349","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106349","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567538973"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106349","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106349","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106349","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567538973"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106349","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106349","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106349","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567538973"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106349","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106349","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"risk":0.23798,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106349","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106349","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106349","date":"2026-10-08","epss":0.00292,"percentile":0.19978}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/567538973"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106349","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106393","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106393","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106393","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559793873"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106393","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106393","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106393","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559793873"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106393","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106393","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106393","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559793873"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106393","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106393","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106393","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559793873"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106393","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106393","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106393","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106393","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106393","date":"2026-10-08","epss":0.00296,"percentile":0.20429}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559793873"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106393","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106238","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/492374387"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106238","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/492374387"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106238","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/492374387"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106238","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/492374387"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106238","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"risk":0.23384,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106238","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106238","date":"2026-10-08","epss":0.00296,"percentile":0.20428}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/492374387"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106238","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68471","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"risk":0.23287499999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."},"relatedVulnerabilities":[{"id":"CVE-2025-68471","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68471","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"risk":0.23287499999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."},"relatedVulnerabilities":[{"id":"CVE-2025-68471","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68471","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"risk":0.23287499999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."},"relatedVulnerabilities":[{"id":"CVE-2025-68471","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106237","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106237","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"risk":0.22878,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553255283"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106237","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106237","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"risk":0.22878,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553255283"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106237","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106237","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"risk":0.22878,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553255283"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106237","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106237","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"risk":0.22878,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553255283"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106237","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106237","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"risk":0.22878,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","metrics":{"baseScore":9.6,"impactScore":6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106237","cwe":"CWE-200","type":"Primary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106237","date":"2026-10-08","epss":0.00246,"percentile":0.14587}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553255283"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106237","description":"Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"5886e793c6b08095","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"e9141be499a1730f","cpes":["cpe:2.3:a:locales:locales:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106308","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"risk":0.22494,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106308","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560055258"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106308","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"risk":0.22494,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106308","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560055258"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106308","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"risk":0.22494,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106308","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560055258"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106308","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"risk":0.22494,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106308","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560055258"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106308","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"risk":0.22494,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106308","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106308","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106308","date":"2026-10-08","epss":0.00276,"percentile":0.18349}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/560055258"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106308","description":"Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"5886e793c6b08095","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"e9141be499a1730f","cpes":["cpe:2.3:a:locales:locales:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"5886e793c6b08095","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"e9141be499a1730f","cpes":["cpe:2.3:a:locales:locales:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.41-12%2Bdeb13u4?arch=all&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103624","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103624","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"risk":0.22436,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103624","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/561660166"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103624","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103624","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"risk":0.22436,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103624","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/561660166"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103624","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103624","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"risk":0.22436,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103624","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/561660166"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103624","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103624","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"risk":0.22436,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103624","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/561660166"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103624","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103624","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"risk":0.22436,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-103624","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103624","cwe":"CWE-416","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-103624","date":"2026-10-08","epss":0.00284,"percentile":0.19199}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/561660166"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103624","description":"Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68468","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"risk":0.2185,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."},"relatedVulnerabilities":[{"id":"CVE-2025-68468","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68468","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"risk":0.2185,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."},"relatedVulnerabilities":[{"id":"CVE-2025-68468","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68468","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"risk":0.2185,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."},"relatedVulnerabilities":[{"id":"CVE-2025-68468","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106201","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106201","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"risk":0.21842000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106201","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517546096"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106201","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106201","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"risk":0.21842000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106201","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517546096"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106201","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106201","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"risk":0.21842000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106201","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517546096"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106201","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106201","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"risk":0.21842000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106201","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517546096"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106201","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106201","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"risk":0.21842000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106201","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106201","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106201","date":"2026-10-08","epss":0.00268,"percentile":0.17358}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/517546096"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106201","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"risk":0.21567,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106409","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559097675"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"risk":0.21567,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106409","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559097675"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"risk":0.21567,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106409","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559097675"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"risk":0.21567,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106409","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559097675"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"risk":0.21567,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106409","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106409","cwe":"CWE-706","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106409","date":"2026-10-08","epss":0.00273,"percentile":0.18095}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/559097675"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106409","description":"Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)"}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:1ae1db78cf1895b58d867dfb44db5e5d7b49ef5300233e14f1bd8333ec6a3149","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76956","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76956","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-08","epss":0.00287,"percentile":0.19503}],"risk":0.21525,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76956","description":"In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content."},"relatedVulnerabilities":[{"id":"CVE-2026-76956","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-08","epss":0.00287,"percentile":0.19503}],"urls":["https://github.com/libexpat/libexpat/pull/1326","https://github.com/libexpat/libexpat/pull/1329"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76956","description":"In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content."}]},{"artifact":{"id":"f95bb02a97e4846d","cpes":["cpe:2.3:a:libxrender1:libxrender1:1\\:0.9.12-1:*:*:*:*:*:*:*"],"name":"libxrender1","purl":"pkg:deb/debian/libxrender1@1%3A0.9.12-1?arch=amd64&distro=debian-13.7&upstream=libxrender","type":"deb","version":"1:0.9.12-1","language":"","licenses":["HPND-sell-variant"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxrender1/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libxrender1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxrender1:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libxrender1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxrender"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88807","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxrender","version":"1:0.9.12-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-88807","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88807","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88807","date":"2026-10-08","epss":0.0026,"percentile":0.16256}],"risk":0.21320000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-88807","description":"A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients."},"relatedVulnerabilities":[{"id":"CVE-2026-88807","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88807","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88807","date":"2026-10-08","epss":0.0026,"percentile":0.16256}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88807","description":"A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34979","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34979","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34979","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34979","date":"2026-10-08","epss":0.00413,"percentile":0.33531}],"risk":0.212695,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34979","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches."},"relatedVulnerabilities":[{"id":"CVE-2026-34979","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34979","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34979","date":"2026-10-08","epss":0.00413,"percentile":0.33531}],"urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fh"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34979","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-41079","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41079","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41079","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41079","date":"2026-10-08","epss":0.00409,"percentile":0.33022}],"risk":0.21267999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41079","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17."},"relatedVulnerabilities":[{"id":"CVE-2026-41079","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41079","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41079","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41079","date":"2026-10-08","epss":0.00409,"percentile":0.33022}],"urls":["https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080","https://github.com/OpenPrinting/cups/commit/d7fe0f521ff3b24676511e747b058362b9a20737","https://github.com/OpenPrinting/cups/security/advisories/GHSA-6wpw-g8g6-wvrv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41079","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106205","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106205","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"risk":0.21138000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106205","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/519499907"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106205","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106205","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"risk":0.21138000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106205","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/519499907"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106205","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106205","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"risk":0.21138000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106205","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/519499907"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106205","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106205","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"risk":0.21138000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106205","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/519499907"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106205","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106205","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"risk":0.21138000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106205","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106205","cwe":"CWE-862","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106205","date":"2026-10-08","epss":0.00271,"percentile":0.1772}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/519499907"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106205","description":"Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.7","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5704","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"risk":0.210525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."},"relatedVulnerabilities":[{"id":"CVE-2026-5704","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66514","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106256","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"risk":0.20619500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106256","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553335319"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106256","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"risk":0.20619500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106256","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553335319"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106256","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"risk":0.20619500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106256","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553335319"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106256","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"risk":0.20619500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106256","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553335319"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106256","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"risk":0.20619500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106256","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106256","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106256","date":"2026-10-08","epss":0.00253,"percentile":0.15412}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553335319"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106256","description":"Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106377","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106377","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"risk":0.20382,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106377","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/520179149"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106377","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106377","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"risk":0.20382,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106377","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/520179149"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106377","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106377","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"risk":0.20382,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106377","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/520179149"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106377","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106377","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"risk":0.20382,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106377","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/520179149"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106377","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106377","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"risk":0.20382,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"},"relatedVulnerabilities":[{"id":"CVE-2026-106377","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106377","cwe":"CWE-362","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106377","date":"2026-10-08","epss":0.00258,"percentile":0.16034}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/520179149"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106377","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106350","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106350","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"risk":0.202935,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106350","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553270559"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106350","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106350","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"risk":0.202935,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106350","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553270559"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106350","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106350","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"risk":0.202935,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106350","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553270559"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106350","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106350","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"risk":0.202935,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106350","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553270559"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106350","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106350","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"risk":0.202935,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106350","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106350","cwe":"CWE-863","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106350","date":"2026-10-08","epss":0.00249,"percentile":0.14815}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/553270559"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106350","description":"Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.7","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:0487fc82d485c6e44b5d5474f45d9740d7009d35040b4f0aad06327293ae5128","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2005-2541","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"risk":0.1996,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."},"relatedVulnerabilities":[{"id":"CVE-2005-2541","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106334","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106334","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"risk":0.19886,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106334","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/556229780"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106334","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106334","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"risk":0.19886,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106334","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/556229780"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"f903274500a51cde","cpes":["cpe:2.3:a:chromium-driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_driver:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_driver:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-driver","purl":"pkg:deb/debian/chromium-driver@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-driver/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-driver/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-driver.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-driver.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106334","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106334","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"risk":0.19886,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106334","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/556229780"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"ec92a335cee31a07","cpes":["cpe:2.3:a:chromium-sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_sandbox:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_sandbox:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-sandbox","purl":"pkg:deb/debian/chromium-sandbox@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-sandbox/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-sandbox/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-sandbox.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-sandbox.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106334","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106334","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"risk":0.19886,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106334","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/556229780"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"8c27715c8b316b97","cpes":["cpe:2.3:a:chromium-shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_shell:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_shell:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-shell","purl":"pkg:deb/debian/chromium-shell@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-shell/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-shell/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-shell.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-shell.list"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106334","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106334","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"risk":0.19886,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"},"relatedVulnerabilities":[{"id":"CVE-2026-106334","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106334","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106334","date":"2026-10-08","epss":0.00244,"percentile":0.14335}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/556229780"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106334","description":"Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)"}]},{"artifact":{"id":"82f1ad0c76021322","cpes":["cpe:2.3:a:chromium:chromium:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium","purl":"pkg:deb/debian/chromium@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.conffiles","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.list"},{"path":"/var/lib/dpkg/info/chromium.postinst","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.postinst"},{"path":"/var/lib/dpkg/info/chromium.prerm","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106342","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106342","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106342","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106342","date":"2026-10-08","epss":0.00244,"percentile":0.14334}],"risk":0.19886,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106342","description":"Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106342","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106342","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106342","date":"2026-10-08","epss":0.00244,"percentile":0.14334}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/512998592"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106342","description":"Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]},{"artifact":{"id":"6aca436b9c858431","cpes":["cpe:2.3:a:chromium-common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium-common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium_common:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium-common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:chromium:chromium_common:154.0.8037.92-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"chromium-common","purl":"pkg:deb/debian/chromium-common@154.0.8037.92-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=chromium","type":"deb","version":"154.0.8037.92-1~deb13u1","language":"","licenses":["Apache-2.0","Apple-license","BSD-2-clause","BSD-3-clause","BSL-1","GPL-2","GPL-2+","GPL-2.0","GPL-3","GPL-3+","ICU","ISC","LGPL-2","LGPL-2+","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","MIT","MPL-1.1","MPL-2.0","Ms-PL","Public-domain","Unicode","zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/chromium-common/copyright","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/usr/share/doc/chromium-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.md5sums","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/chromium-common.list","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.list"},{"path":"/var/lib/dpkg/info/chromium-common.shlibs","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.shlibs"},{"path":"/var/lib/dpkg/info/chromium-common.triggers","layerID":"sha256:994e935cfea909d532fadd00dc6ad470ad069afc0765c1c7ed72ac80ca9b6f08","accessPath":"/var/lib/dpkg/info/chromium-common.triggers"}],"upstreams":[{"name":"chromium"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106342","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"chromium","version":"154.0.8037.92-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106342","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106342","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106342","date":"2026-10-08","epss":0.00244,"percentile":0.14334}],"risk":0.19886,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106342","description":"Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"},"relatedVulnerabilities":[{"id":"CVE-2026-106342","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106342","cwe":"CWE-200","type":"Secondary","source":"chrome-cve-admin@google.com"}],"epss":[{"cve":"CVE-2026-106342","date":"2026-10-08","epss":0.00244,"percentile":0.14334}],"urls":["https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","https://issues.chromium.org/issues/512998592"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106342","description":"Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)"}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T20:03:40.852Z","grype_db_version":"2026-10-09T06:32:32.000Z"}