Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.2 Browsers CVE-2026-106186 CVE-2026-106271 CVE-2026-106188 CVE-2026-106244

Google Chrome Stable Update Fixes Five Vulnerabilities (CVE-2026-106186, CVE-2026-106271, CVE-2026-106188, CVE-2026-106244, CVE-2026-106279)

Google has released Chrome 155.0.8059.39 for Desktop, fixing five vulnerabilities including two rated high severity involving sandbox escape and site isolation bypass risks.

AI summary

Google has published a Stable Channel update for Chrome on Desktop, addressing five distinct vulnerabilities disclosed under the Chromium security program. The issues span different components of the browser, including credential handling, worker processes, sign-in functionality, permissions handling, and password management. All five are fixed in Chrome version 155.0.8059.39. None of the vulnerabilities are reported as known to be exploited or to have public exploit code available.

Five vulnerabilities fixed in a single Chrome update

Google released a Stable Channel update for Chrome on Desktop that resolves five separate vulnerabilities, each assigned its own CVE identifier: CVE-2026-106186 (CredentialProvider, uncontrolled search path element), CVE-2026-106271 (Workers, missing authorization allowing a site isolation bypass), CVE-2026-106188 (SignIn on Android, confused deputy issue), CVE-2026-106244 (Permissions, incorrect authorization), and CVE-2026-106279 (Passwords on iOS, incorrect reference resolution). The fixes are bundled in a single release, version 155.0.8059.39.

Underlying weaknesses vary by component

Each vulnerability stems from a different root cause. CVE-2026-106186 involves an uncontrolled search path element (CWE-427) in the CredentialProvider component, which could let a local attacker load a local program to execute code outside the sandbox. CVE-2026-106271 is a missing authorization flaw (CWE-862) in Workers, allowing a remote attacker who has already compromised a renderer process to bypass site isolation using a crafted PDF file. CVE-2026-106188 is a confused deputy issue (CWE-441) in SignIn on Android, letting a remote attacker bypass system access restrictions into a privileged page via a crafted HTML page. CVE-2026-106244 is an incorrect authorization issue (CWE-863) in Permissions, allowing a remote attacker to bypass system access restrictions via crafted network traffic. CVE-2026-106279 involves incorrect reference resolution (CWE-706) in Passwords on iOS, which could let a local attacker who has compromised the renderer process execute arbitrary code outside the sandbox via a local program.

Severity varies, but two issues carry high CVSS scores

Chromium internally classifies CVE-2026-106186 as Low severity and CVE-2026-106271, CVE-2026-106188, and CVE-2026-106279 as Medium severity, while CVE-2026-106244 is also Medium. However, independent CVSS scoring places two of these notably higher: CVE-2026-106186 scores 8.6 and CVE-2026-106271 scores 8.1, both reflecting high potential impact on confidentiality, integrity, or availability if exploited. CVE-2026-106279 scores 7.4, CVE-2026-106188 scores 7.1, and CVE-2026-106244 scores 6.5. None of the five vulnerabilities are flagged as known to be exploited in the wild, and no public exploit code has been reported.

Chrome users across Desktop, Android, and iOS

The update applies to Google Chrome on Desktop generally. Two of the five vulnerabilities specifically affect platform variants: CVE-2026-106188 affects Chrome on Android, and CVE-2026-106279 affects Chrome on iOS. The remaining three (CVE-2026-106186, CVE-2026-106271, CVE-2026-106244) are described without a platform-specific qualifier in the advisory text, though CVE-2026-106186 is noted as affecting Chrome on Windows specifically.

Versions prior to 155.0.8059.39

All five vulnerabilities affect Google Chrome versions prior to 155.0.8059.39. No specific starting version for the affected range is provided in the fact package.

Fixed in Chrome 155.0.8059.39

Google has released Chrome version 155.0.8059.39 for Desktop, which contains fixes for all five vulnerabilities described in this briefing.

Update Chrome as soon as possible

Site owners, administrators, and end users running Google Chrome should ensure their browser is updated to version 155.0.8059.39 or later. Chrome typically updates automatically, but users can verify their version via the browser's settings menu (About Google Chrome) and trigger a manual check if needed. Given the high CVSS scores on two of the five issues, timely patching is advised even though no active exploitation has been reported.

PatchBriefing score

5.2 / 10 · Medium

Official CVSS: 8.6

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

The Patchwire scores for these five vulnerabilities range from 4.8 to 5.2, driven primarily by their CVSS base scores (ranging from 6.5 to 8.6) and the large installed base of Google Chrome, which contributes a small popularity factor to each score. None of the vulnerabilities are known to be exploited in the wild, have public exploit code, or qualify as unauthenticated-remote-and-no-user-interaction-required in every case, which keeps the scores in the moderate range despite the sometimes high CVSS base values. CVE-2026-106244 and CVE-2026-106188 received a modest score boost for being exploitable without authentication, and CVE-2026-106271 and CVE-2026-106244 for not requiring user interaction.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has released Chrome version 155.0.8059.39 for Desktop, which contains fixes for all five vulnerabilities described in this briefing.

How this was built

6 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Five Vulnerabilities (CVE-2026-106186, CVE-2026-106271, CVE-2026-106188, CVE-2026-106244, CVE-2026-106279)
1 article · 6 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email