Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 Browsers CVE-2026-106352 CVE-2026-106201 CVE-2026-106308 CVE-2026-106235

Google Chrome Stable Update Fixes Eight Vulnerabilities, Including Sandbox Escape Risks

Google has released Chrome 155.0.8059.39 for desktop, fixing eight vulnerabilities including use-after-free, type confusion, and race condition flaws in V8, WebAudio, Media, and Autofill that could allow remote code execution inside the sandbox or disclosure of sensitive information.

AI summary

Google has published a Stable Channel update for Chrome on desktop, addressing eight distinct vulnerabilities disclosed under separate CVE identifiers. The flaws span several Chrome components, including the V8 JavaScript engine, WebAudio, Media, and Autofill, and were rated Medium to High in Chromium's internal severity classification. All eight issues are fixed in Chrome version 155.0.8059.39. There is no evidence in the available source material that any of these vulnerabilities have been exploited in the wild.

What happened

Google released a Stable Channel update for Chrome on desktop that fixes eight separate vulnerabilities: CVE-2026-106352 (incorrect authorization in WebProtect), CVE-2026-106201 (race condition in V8), CVE-2026-106308 (incorrect reference resolution in Autofill, on Android), CVE-2026-106235 (use after free in WebAudio), CVE-2026-106203 (incomplete cleanup in Autofill, on iOS), CVE-2026-106240 (type confusion in V8), CVE-2026-106190 (use after free in Media), and CVE-2026-106341 (type confusion in V8). All eight were disclosed together in the same vendor release.

Technical causes

The vulnerabilities stem from several different underlying weaknesses. CVE-2026-106201 and CVE-2026-106240 and CVE-2026-106341 involve V8 issues: a race condition (CVE-2026-106201) and two instances of type confusion (CVE-2026-106240, CVE-2026-106341), which can allow an attacker to execute arbitrary code inside the browser's sandbox via a crafted HTML page. CVE-2026-106235 and CVE-2026-106190 are use-after-free bugs in WebAudio and Media respectively, which could similarly enable sandboxed code execution. CVE-2026-106352 is an incorrect authorization issue in WebProtect (CWE-863) that could expose sensitive information to an attacker using social engineering. CVE-2026-106308 (on Android) and CVE-2026-106203 (on iOS) are issues in Autofill — incorrect reference resolution and incomplete cleanup, respectively — that could also leak sensitive information via a crafted HTML page combined with social engineering.

Why it matters

Several of these vulnerabilities (CVE-2026-106201, CVE-2026-106235, CVE-2026-106190, CVE-2026-106240, CVE-2026-106341) could allow an attacker to execute arbitrary code within Chrome's sandbox simply by getting a user to visit a crafted HTML page. While sandboxing limits the immediate impact, successful exploitation of sandbox escape primitives is a known stepping stone toward broader compromise when chained with other flaws. The remaining issues (CVE-2026-106352, CVE-2026-106308, CVE-2026-106203) could expose sensitive user information, such as autofill data, to a remote attacker who convinces a victim to interact with malicious content. All eight vulnerabilities share a CVSS base score of 8.8, reflecting high impact on confidentiality, integrity, and availability, combined with low attack complexity and no required privileges, though all require some form of user interaction.

Who is affected

All users running Google Chrome on desktop prior to version 155.0.8059.39 are affected by the core set of vulnerabilities. Two of the issues are platform-specific: CVE-2026-106308 affects Chrome on Android, and CVE-2026-106203 affects Chrome on iOS. Given Chrome's broad installation base, this affects a very large number of individual users and organizations.

Affected versions

Google Chrome versions prior to 155.0.8059.39 are affected by all eight vulnerabilities described in this release. No specific earliest-affected version was disclosed in the available source material.

Fixes and mitigation

Google has fixed all eight vulnerabilities in Chrome version 155.0.8059.39, released through the Stable Channel for desktop. No workarounds beyond updating are mentioned in the available source material.

Recommended action

Update Google Chrome to version 155.0.8059.39 or later as soon as possible. Chrome typically updates automatically, but users and administrators should verify the installed version via the browser's About page and restart the browser to apply the update. Organizations managing Chrome deployments at scale should confirm that managed update policies have pushed this version to all endpoints.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Why this score

Each of the eight vulnerabilities carries a CVSS base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), reflecting network-exploitable issues with low attack complexity and no privileges required, but requiring user interaction, with high impact on confidentiality, integrity, and availability if exploited. The computed PatchBriefing score of 5.9 reflects this CVSS base contribution alongside the facts that the vulnerabilities are remotely exploitable without authentication and affect an extremely widely deployed product (contributing minor additional weight), while there is no evidence of known exploitation in the wild, no public exploit code, and a fix is already available — all of which keep the score from being higher.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has fixed all eight vulnerabilities in Chrome version 155.0.8059.39, released through the Stable Channel for desktop. No workarounds beyond updating are mentioned in the available source material.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Eight Vulnerabilities, Including Sandbox Escape Risks
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email