Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.4 Browsers CVE-2026-106323 CVE-2026-106375 CVE-2026-106227 CVE-2026-106197

Google Chrome 155.0.8059.39 Fixes Eight High-Severity Vulnerabilities, Including Multiple Use-After-Free Bugs

Google has released Chrome 155.0.8059.39 to address eight vulnerabilities, including several use-after-free flaws and sandbox-related weaknesses, each capable of enabling arbitrary code execution via a crafted HTML page.

AI summary

Google has published a Stable Channel update for Chrome on desktop, bundled with fixes on iOS and Android, addressing eight separate vulnerabilities disclosed on 2026-10-06. The flaws span multiple Chrome components, including Core, Browser, SiteIsolation, Media, Permissions, ANGLE, and Dawn, and several could allow a remote attacker to execute arbitrary code outside the browser sandbox through a specially crafted HTML page. The vendor has assigned Chromium security severity ratings ranging from Critical to Low across these issues. No evidence of known or active exploitation has been reported for any of these vulnerabilities as of publication.

What Happened

Google released a Stable Channel update for Chrome on desktop, fixing eight distinct vulnerabilities identified as CVE-2026-106323, CVE-2026-106375, CVE-2026-106227, CVE-2026-106197, CVE-2026-102322, CVE-2026-106417, CVE-2026-106237, and CVE-2026-106419. The update is documented in the official Chrome Releases blog post. All eight issues are fixed in version 155.0.8059.39.

Technical Causes

The vulnerabilities stem from several distinct root causes across different Chrome components. CVE-2026-106197 and CVE-2026-106227 are use-after-free flaws (CWE-416) in the Browser and Core components, respectively. CVE-2026-106419 is a use-after-free in ANGLE, affecting Chrome on Android. CVE-2026-102322 is an incorrect authorization issue (CWE-863) in SiteIsolation. CVE-2026-106323 is a missing authorization flaw (CWE-862) specific to Chrome on iOS. CVE-2026-106375 involves incomplete cleanup (CWE-459) in the Dawn component. CVE-2026-106417 is an integer overflow (CWE-190) in the Media component. CVE-2026-106237 is an information leak (CWE-200) in Permissions that could bypass site isolation. In each case, Google states the flaw could be triggered via a crafted HTML page.

Why It Matters

Most of these vulnerabilities are rated with a CVSS base score of 9.6, reflecting network-exploitable conditions with low attack complexity, no privileges required, and high impact on confidentiality, integrity, and availability once a user interacts with malicious content. Several, including CVE-2026-106197, CVE-2026-106227, CVE-2026-106419, and CVE-2026-102322, are described by the vendor as allowing arbitrary code execution outside the sandbox — the mechanism designed to contain damage from a compromised renderer process. A successful exploit chain combining these issues could potentially lead to full system compromise from simply visiting a malicious web page.

Who Is Affected

All users running Google Chrome on desktop are affected by the majority of these issues. CVE-2026-106323 specifically affects Chrome for iOS, and CVE-2026-106419 specifically affects Chrome on Android, in addition to desktop exposure for the remaining vulnerabilities.

Affected Versions

All versions of Google Chrome prior to 155.0.8059.39 are affected by these vulnerabilities, according to the vendor's advisory.

Fixes and Mitigation

Google has released version 155.0.8059.39, which resolves all eight vulnerabilities described in this briefing. The fix is available through Chrome's standard update mechanism.

Recommended Action

Update Google Chrome to version 155.0.8059.39 or later as soon as possible. Chrome typically updates automatically, but users and administrators should verify the update has been applied by checking the browser's version via the "About Chrome" menu, and restart the browser to complete the update. Organizations managing Chrome deployments via enterprise policy should confirm the update has propagated across all endpoints.

PatchBriefing score

6.4 / 10 · Medium

Official CVSS: 9.6

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

The patchwire score of 6.4 reflects a combination of factors: a high CVSS base score of 9.6 across the affected issues (contributing 5.28 points, the largest component), the fact that these are remotely exploitable without authentication (contributing 0.6 points), and the broad popularity of the affected product as a browser used by a very large user base (contributing 0.5 points). The score is moderated by the absence of confirmed active exploitation, no known public exploit code, and the fact that a fix is already available — all of which would otherwise increase urgency. Despite the high CVSS scores for individual issues, the overall patchwire score reflects that exploitation requires user interaction (visiting a crafted page) and no evidence currently indicates these flaws are being exploited in the wild.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has released version 155.0.8059.39, which resolves all eight vulnerabilities described in this briefing. The fix is available through Chrome's standard update mechanism.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome 155.0.8059.39 Fixes Eight High-Severity Vulnerabilities, Including Multiple Use-After-Free Bugs
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email