Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.7 Browsers CVE-2026-106377 CVE-2026-106393 CVE-2026-106228 CVE-2026-106363

Google Chrome Stable Update Fixes Eight Vulnerabilities, Including High-Severity Sandbox Escapes

Google has released Chrome 155.0.8059.39 for Desktop, fixing eight vulnerabilities including two high-severity race condition and use-after-free bugs that could allow sandbox escape via a compromised renderer process.

AI summary

Google has published a Stable Channel update for Chrome Desktop, version 155.0.8059.39, addressing eight separate vulnerabilities disclosed as CVE-2026-106377, CVE-2026-106393, CVE-2026-106228, CVE-2026-106363, CVE-2026-106412, CVE-2026-106238, CVE-2026-106221, and CVE-2026-106247. According to Chromium's internal severity ratings, two of these issues are rated High, five are rated Medium, and one is rated Low. All issues require that an attacker has already compromised the browser's renderer process, or in some cases rely on social engineering, as a precondition for exploitation outside the sandbox.

What happened

Google released a Stable Channel update for Chrome Desktop bringing the browser to version 155.0.8059.39. The update addresses eight distinct vulnerabilities across different Chrome components: Fonts (two issues), Storage, Google Lens, FullScreen, Core (Mac-specific), WebAPKs (Android-specific), and ANGLE. Each vulnerability was assigned its own CVE identifier and disclosed in the same vendor release.

Technical causes

The vulnerabilities stem from several distinct weaknesses: CVE-2026-106377 and CVE-2026-106238 are race conditions in the Fonts component (CWE-362). CVE-2026-106393 is a use-after-free in Storage (CWE-416). CVE-2026-106228 and CVE-2026-106221 are confused deputy issues (CWE-441) in Google Lens and WebAPKs respectively. CVE-2026-106363 is a missing authorization flaw (CWE-862) in FullScreen. CVE-2026-106412 is a race condition (CWE-367) in Core, specific to Chrome on Mac. CVE-2026-106247 is a buffer overflow (CWE-122) in ANGLE. In most cases, the vendor advisory states that exploitation requires a remote attacker who has already compromised the renderer process, with several issues also requiring social engineering or user interaction via a crafted HTML page.

Why it matters

Each of these vulnerabilities carries a CVSS base score of 8.3, reflecting high potential impact on confidentiality, integrity, and availability if successfully exploited. The two High-severity issues (CVE-2026-106377 and CVE-2026-106393) are particularly notable because they could allow an attacker who has already compromised the renderer process to execute arbitrary code outside the Chrome sandbox — effectively breaking one of the browser's core security boundaries. The remaining issues (rated Medium or Low by Chromium) still carry the same CVSS base score but generally describe outcomes described as 'potentially' allowing sandbox escape, or require social engineering, narrowing their practical exploitability.

Who is affected

All users running Google Chrome on Desktop prior to version 155.0.8059.39 are affected by the majority of these issues. Two vulnerabilities are platform-specific: CVE-2026-106412 affects Chrome on Mac specifically, and CVE-2026-106221 affects Chrome on Android specifically (via WebAPKs).

Affected versions

All versions of Google Chrome prior to 155.0.8059.39 are affected by one or more of these vulnerabilities, as described in the vendor's fixed-version claims.

Fixes and mitigation

Google has fixed all eight vulnerabilities in Chrome version 155.0.8059.39, released on the Stable Channel for Desktop. No known exploitation in the wild and no public exploit code have been reported for any of these issues.

Recommended action

Site owners and developers should ensure Google Chrome is updated to version 155.0.8059.39 or later as soon as possible. Chrome typically updates automatically, but administrators managing fleets of devices should verify the update has been applied, particularly on Mac and Android platforms where platform-specific issues were also fixed.

PatchBriefing score

5.7 / 10 · Medium

Official CVSS: 8.3

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

The Patchwire score of 5.7 for each of these eight vulnerabilities is driven primarily by the CVSS base score of 8.3, which contributes 4.57 points. An additional 0.6 points come from the 'unauthenticated_remote' factor, and 0.5 points from Chrome's extremely high product popularity (reflecting the scale of the user base at risk). There is no contribution from known exploitation, public exploit availability, or EPSS, as none of these have been reported or are currently known for these issues. No deduction was applied for 'no fix available' since fixes are already released. The score reflects a technically serious but not actively exploited set of issues, each requiring additional preconditions (renderer compromise or social engineering) to be exploited outside the sandbox.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has fixed all eight vulnerabilities in Chrome version 155.0.8059.39, released on the Stable Channel for Desktop. No known exploitation in the wild and no public exploit code have been reported for any of these issues.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Eight Vulnerabilities, Including High-Severity Sandbox Escapes
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email