Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 Browsers CVE-2026-106349 CVE-2026-106314 CVE-2026-106283 CVE-2026-106373

Google Chrome Stable Update Fixes Eight Vulnerabilities, Including Multiple Use-After-Free Flaws

Google has released Chrome 155.0.8059.39 for desktop, fixing eight vulnerabilities including four use-after-free issues that could allow sandboxed code execution via crafted HTML pages.

AI summary

Google has published a Stable Channel update for Chrome on desktop, addressing eight separate vulnerabilities identified in the Chrome Releases blog and subsequently registered in the NVD. The fixes are consolidated in version 155.0.8059.39. The issues span several Chrome components, including the V8 JavaScript engine, Bluetooth, Autofill, media and font handling, and the HTML parser. Four of the eight vulnerabilities are use-after-free bugs that could, according to the vendor description, allow a remote attacker to execute arbitrary code inside Chrome's sandbox via a specially crafted HTML page.

What happened

Google released a Stable Channel update for Chrome on desktop that fixes eight vulnerabilities. According to the vendor advisory, these include four use-after-free (CWE-416) issues in V8, Streaming, Fonts, Parser, and Media components, as well as authorization-related issues (CWE-863, CWE-862) in Bluetooth and Autofill. Chromium rated the individual issues as High, Medium, or Low severity depending on the component affected.

Technical cause

The vulnerabilities fall into two categories. Use-after-free issues (CVE-2026-106349 in V8, CVE-2026-106283 in Streaming, CVE-2026-106373 in Fonts on Windows, CVE-2026-106411 in the Parser, and CVE-2026-106423 in Media) occur when memory is accessed after it has been freed, which can be leveraged to execute arbitrary code inside Chrome's sandbox via a crafted HTML page. Separately, incorrect or missing authorization checks (CVE-2026-106314 in Bluetooth, CVE-2026-106249 in Autofill on Android, and CVE-2026-106225 in Autofill) could allow a remote attacker to obtain sensitive information, also via a crafted HTML page. Some of these issues reportedly require social engineering to be triggered, per the vendor description.

Why it matters

All eight vulnerabilities carry a CVSS base score of 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), reflecting network-based attack vectors, low attack complexity, no privileges required, and high impact on confidentiality, integrity, and availability once triggered. User interaction (visiting a crafted page) is required in all cases. The use-after-free issues are of particular concern because they are described as enabling arbitrary code execution inside the sandbox, which is a step toward full system compromise if chained with a sandbox escape.

Who is affected

All users running Google Chrome on desktop prior to version 155.0.8059.39 are affected. One issue (CVE-2026-106373) is specific to Chrome on Windows, and another (CVE-2026-106249) is specific to Chrome on Android. The remaining issues affect Chrome generally, per the vendor description.

Affected versions

Chrome versions prior to 155.0.8059.39 are affected by these vulnerabilities, according to the vendor advisory.

Fixes and mitigation

Google has fixed all eight vulnerabilities in Chrome version 155.0.8059.39. The fix is distributed through Chrome's standard update mechanism as part of the Stable Channel release.

Recommended action

Update Chrome to version 155.0.8059.39 or later as soon as possible. Chrome typically updates automatically, but users and administrators should verify the installed version via the browser's 'About Chrome' menu and restart the browser to complete the update. Organizations managing Chrome deployments at scale should confirm that managed update policies are not blocking this release.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Why this score

The patchwire score of 5.9 for each of these eight CVEs reflects a CVSS base score of 8.8 (contributing 4.84 points), combined with a small additional contribution for unauthenticated remote attack vectors (0.6) and the high popularity of the affected product (0.5). There is no evidence of known exploitation, public exploit code, or EPSS scoring data available for any of these issues, so no additional contribution was added for those factors. User interaction is required in all cases, which also limits the score contribution from that factor.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has fixed all eight vulnerabilities in Chrome version 155.0.8059.39. The fix is distributed through Chrome's standard update mechanism as part of the Stable Channel release.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Eight Vulnerabilities, Including Multiple Use-After-Free Flaws
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email