Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.7 Browsers CVE-2026-106293 CVE-2026-106194 CVE-2026-106409 CVE-2026-106233

Google Chrome Stable Update Fixes Eight Vulnerabilities Including High-Severity Type Confusion and Use-After-Free Flaws

Google has released Chrome 155.0.8059.39 for desktop, fixing eight vulnerabilities including type confusion in ANGLE, a use-after-free in Metrics, a race condition in Fonts, and several missing-authorization and reference-resolution issues affecting Mac.

AI summary

Google has published a Stable Channel update for Google Chrome on desktop, addressing eight separate vulnerabilities identified by the vendor. The issues span several Chrome components, including ANGLE, WebAppInstalls, Metrics, Fonts, Sandbox, and Actor, and carry Chromium-assigned severities ranging from Low to High. All eight are fixed in Chrome 155.0.8059.39. No evidence of active exploitation or public proof-of-concept exploit code has been reported for any of these issues.

What Happened

Google released a Stable Channel update for Chrome on desktop that resolves eight distinct vulnerabilities: a type confusion in ANGLE (CVE-2026-106293, Chromium severity High), a missing authorization issue in WebAppInstalls (CVE-2026-106194, Medium), an incorrect reference resolution in WebAppInstalls affecting Mac (CVE-2026-106409, Medium), a use-after-free in Metrics (CVE-2026-106233, High), a race condition in Fonts (CVE-2026-106426, High), a privilege elevation issue in Sandbox affecting Mac (CVE-2026-106378, Medium), a buffer overflow in Fonts (CVE-2026-106292, Medium), and a missing authorization issue in Actor (CVE-2026-106191, Low). All eight were disclosed together in the same vendor release.

Technical Cause

The vulnerabilities stem from different underlying weaknesses across Chrome components. CVE-2026-106293 is a type confusion (CWE-843) in ANGLE. CVE-2026-106194 and CVE-2026-106191 involve missing authorization (CWE-862) in WebAppInstalls and Actor respectively. CVE-2026-106409 is an incorrect reference resolution (CWE-706) in WebAppInstalls, specific to Mac. CVE-2026-106233 is a use-after-free (CWE-416) in Metrics. CVE-2026-106426 is a race condition (CWE-362) in Fonts. CVE-2026-106378 is a privilege elevation issue (CWE-250) in Sandbox, specific to Mac. CVE-2026-106292 is a buffer overflow (CWE-122) in Fonts. According to the vendor description, most of these require a remote attacker who has already compromised the Chrome renderer process, after which the flaw could allow code execution outside the sandbox via a crafted HTML page, or, in the case of CVE-2026-106409, via crafted network traffic.

Why It Matters

These vulnerabilities are described as sandbox-escape issues: an attacker who has already achieved renderer-process compromise through a separate, unspecified vector could use one of these flaws to execute arbitrary code outside Chrome's sandbox. This two-stage requirement limits exploitability for most issues on this list, but it also means these flaws could be chained with other vulnerabilities in a real-world attack. Chromium rated several of the fixed issues as High severity.

Who Is Affected

All Google Chrome desktop users running versions prior to 155.0.8059.39 are affected by one or more of these issues. Two of the vulnerabilities (CVE-2026-106409 and CVE-2026-106378) are specific to Chrome on Mac.

Affected Versions

Google Chrome versions prior to 155.0.8059.39 are affected. The fact package does not specify a lower version bound for when these issues were introduced.

Fixes and Mitigation

Google has fixed all eight vulnerabilities in Google Chrome 155.0.8059.39 for desktop, released via the Stable Channel. No additional mitigation steps beyond updating are described in the available facts.

Recommended Action

Update Google Chrome to version 155.0.8059.39 or later. Chrome typically updates automatically, but users and administrators should verify the installed version via the browser's About page and restart the browser to complete the update.

PatchBriefing score

5.7 / 10 · Medium

Official CVSS: 8.3

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

Each of these eight CVEs carries a CVSS base score of 8.3 (AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H), reflecting network-exploitable, high-impact flaws that require high attack complexity and user interaction. The computed PatchBriefing score of 5.7 reflects the CVSS base score contribution (4.57) plus a modest increase for the unauthenticated network attack vector (0.6) and Chrome's broad install base (0.5). No points were added for known exploitation, public exploit code, or EPSS data, as none of these were present in the available facts. No points were deducted for missing fixes, since a fix is available for all eight issues.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has fixed all eight vulnerabilities in Google Chrome 155.0.8059.39 for desktop, released via the Stable Channel. No additional mitigation steps beyond updating are described in the available facts.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Eight Vulnerabilities Including High-Severity Type Confusion and Use-After-Free Flaws
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email