Medium · 6.4 Browsers CVE-2026-106239 CVE-2026-106372 CVE-2026-106234 CVE-2026-106211
Google Chrome Stable Update Fixes Eight Vulnerabilities, Including High-Severity Sandbox Escape Risks
Google has released a Stable Channel update for Chrome on Desktop and Android fixing eight vulnerabilities, several of which could allow a remote attacker to execute code outside or inside the browser sandbox. All issues are resolved in version 155.0.8059.39.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 3d ago · view ↗
- NVD (NIST) database 3d ago · view ↗
- NVD (NIST) database 3d ago · view ↗
- NVD (NIST) database 2d ago · view ↗
- NVD (NIST) database 1d ago · view ↗
- NVD (NIST) database 1d ago · view ↗
- NVD (NIST) database 3d ago · view ↗
- NVD (NIST) database 2d ago · view ↗
AI summary
Google has published a Stable Channel update for Chrome that addresses eight distinct vulnerabilities disclosed under CVE-2026-106239, CVE-2026-106372, CVE-2026-106234, CVE-2026-106211, CVE-2026-106195, CVE-2026-106294, CVE-2026-106257, and CVE-2026-106274. The update is described in Google's official Chrome Releases blog post. All eight issues are fixed in Chrome version 155.0.8059.39. No evidence of active exploitation or public exploit code has been reported for any of these vulnerabilities.
Eight vulnerabilities fixed in one update
Google's Stable Channel update for Chrome resolves eight separate vulnerabilities. These include an integer overflow in WebGL (CVE-2026-106239), incorrect authorization in the browser UI (CVE-2026-106372), a use-after-free in the Network component (CVE-2026-106234), a use-after-free in TabStrip (CVE-2026-106211), incorrect authorization in Chromoting on Mac (CVE-2026-106195), incomplete cleanup in Chromoting on Mac (CVE-2026-106294), a use-after-free in HTML processing (CVE-2026-106257), and incorrect reference resolution in the Browser component on Mac (CVE-2026-106274). All are fixed in Chrome 155.0.8059.39.
Underlying weaknesses
The vulnerabilities stem from several distinct coding weaknesses: integer overflow (CWE-190) in CVE-2026-106239; incorrect authorization (CWE-863) in CVE-2026-106372 and CVE-2026-106195; use-after-free (CWE-416) in CVE-2026-106234, CVE-2026-106211, and CVE-2026-106257; incomplete cleanup (CWE-459) in CVE-2026-106294; and incorrect reference resolution (CWE-706) in CVE-2026-106274. Several of the use-after-free and overflow conditions could, according to Chromium's own severity ratings, allow code execution outside or inside the browser's sandbox.
Why these fixes matter
Chromium rated several of these bugs High severity, including the WebGL integer overflow (CVE-2026-106239) and the TabStrip and HTML use-after-free issues (CVE-2026-106211, CVE-2026-106257), because they could potentially allow a remote attacker to execute arbitrary code via a crafted HTML page, in some cases outside the browser's sandbox protections. CVE-2026-106372 and CVE-2026-106234 were rated Medium and Low by Chromium respectively despite high CVSS scores, and CVE-2026-106234 additionally requires a crafted Chrome extension and social engineering to exploit. The Mac-specific Chromoting issues (CVE-2026-106195, CVE-2026-106294) could let a remote attacker bypass system access restrictions via crafted network traffic, without requiring user interaction according to the CVSS vectors provided.
Who is affected
All users running Google Chrome on affected platforms prior to version 155.0.8059.39 are affected. CVE-2026-106239 specifically affects Chrome on Android. CVE-2026-106195 and CVE-2026-106294 specifically affect Chrome on Mac. CVE-2026-106274 also specifically affects Chrome on Mac. The remaining vulnerabilities (CVE-2026-106372, CVE-2026-106234, CVE-2026-106211, CVE-2026-106257) are described generally for Google Chrome without a specific platform limitation noted in the available facts.
Affected and fixed versions
All eight vulnerabilities affect versions of Google Chrome prior to 155.0.8059.39. The fix for all eight issues is included in Chrome version 155.0.8059.39.
Fix available
Google has released Chrome version 155.0.8059.39, which resolves all eight vulnerabilities described in this briefing. The fix is distributed through Chrome's Stable Channel update mechanism.
What to do
Update Google Chrome to version 155.0.8059.39 or later as soon as possible. Chrome typically updates automatically, but users and administrators should verify the installed version via Chrome's About page and restart the browser to apply the update. Organizations managing Chrome deployments at scale should confirm the update has propagated across managed devices.
PatchBriefing score
6.4 / 10 · Medium
Official CVSS: 9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Why this score
The highest-scored vulnerability in this batch, CVE-2026-106239, carries a CVSS base score of 9.6 and a PatchBriefing score of 6.4. The score reflects the high CVSS base score contribution (5.28), the fact that the vulnerability can be reached remotely by an unauthenticated attacker (contribution 0.6), and the product's very high popularity (Chrome, over 1 billion installations, contribution 0.5). The score is moderated because no known exploitation in the wild, no public exploit code, and no EPSS data were reported, and because user interaction is required to trigger the issue. CVE-2026-106372 and CVE-2026-106234 share the same CVSS score and PatchBriefing score (6.4) under the same reasoning. The Chromoting-related issues (CVE-2026-106195, CVE-2026-106294) score slightly lower (6.3) due to a marginally lower CVSS base (9.1), though they gain a small additional contribution because no user interaction is required. The remaining three vulnerabilities (CVE-2026-106211, CVE-2026-106257, CVE-2026-106274) score 5.9, reflecting a CVSS base of 8.8 under the same absence of known exploitation or public exploit evidence.
Affected versions
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
Reported fixes
Google has released Chrome version 155.0.8059.39, which resolves all eight vulnerabilities described in this briefing. The fix is distributed through Chrome's Stable Channel update mechanism.
How this was built
9 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email