Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.6 Browsers CVE-2026-106301 CVE-2026-106199 CVE-2026-106198 CVE-2026-106205

Google Chrome 155 Patches Eight Medium-to-High Severity Vulnerabilities

Google has released Chrome 155.0.8059.39 for desktop, fixing eight vulnerabilities including authorization bypasses, site isolation bypasses, and a code injection flaw affecting Android, iOS, and desktop components.

AI summary

Google has published a Stable Channel update for Chrome, addressing eight distinct vulnerabilities identified through its internal security review process. The issues span multiple browser components — including FileSystem, Accessibility, Navigation, Passwords, ReaderMode, and Contextual Tasks — and affect desktop, Android, and iOS builds. All eight vulnerabilities are fixed in Chrome version 155.0.8059.39. None of the vulnerabilities are reported as actively exploited, and no public exploit code has been identified.

What Happened

On October 6, 2026, Google released a Stable Channel update for Chrome on desktop that resolves eight security vulnerabilities, each assigned a separate CVE identifier: CVE-2026-106301, CVE-2026-106199, CVE-2026-106198, CVE-2026-106205, CVE-2026-106403, CVE-2026-106189, CVE-2026-106367, and CVE-2026-106196. The vulnerabilities involve a mix of weaknesses, including missing authorization checks (CWE-862), incorrect authorization (CWE-863), a confused deputy issue (CWE-441), and a code injection flaw (CWE-94). Most of the issues could allow a remote attacker who has already compromised a Chrome renderer process to bypass site isolation, bypass web origin policy, or access privileged pages via a crafted HTML page.

Technical Cause

The eight vulnerabilities stem from authorization and access-control weaknesses in distinct Chrome components: - CVE-2026-106301 (CWE-441, confused deputy) affects the Contextual Tasks component, allowing bypass of system access restrictions into a privileged page. - CVE-2026-106199 (CWE-863, incorrect authorization) affects the Actor component on Android, potentially bypassing site isolation. - CVE-2026-106198 (CWE-862, missing authorization) affects the FileSystem component, allowing bypass of web origin policy. - CVE-2026-106205 (CWE-862, missing authorization) affects the Passwords component on Android, allowing site isolation bypass. - CVE-2026-106403 (CWE-863, incorrect authorization) affects the Accessibility component, allowing site isolation bypass. - CVE-2026-106189 (CWE-94, code injection) affects the ReaderMode component on iOS, allowing web origin policy bypass via social engineering. - CVE-2026-106367 (CWE-862, missing authorization) affects the Mobile component on Android, potentially allowing a local attacker to execute code outside the sandbox via a co-installed app. - CVE-2026-106196 (CWE-862, missing authorization) affects the Navigation component on iOS, allowing web origin policy bypass into a privileged page. Most of these require that an attacker has already compromised the renderer process, a precondition that limits them to exploitation chains rather than standalone remote attacks, with the exception of CVE-2026-106189 and CVE-2026-106367, which rely on social engineering.

Why It Matters

These vulnerabilities, if chained with a renderer compromise or combined with social engineering, could let an attacker break out of Chrome's sandboxing and isolation protections — bypassing site isolation or web origin policy to access privileged content or, in one Android case, execute code outside the sandbox entirely. While each flaw individually depends on a precondition (a compromised renderer process, a co-installed app, or user interaction via social engineering), the breadth of affected components across desktop, Android, and iOS underscores the value of applying the update across all platforms where Chrome is deployed.

Who Is Affected

Users and organizations running Google Chrome prior to version 155.0.8059.39 are affected. Some vulnerabilities are specific to Android (CVE-2026-106199, CVE-2026-106205, CVE-2026-106367) or iOS (CVE-2026-106189, CVE-2026-106196) builds, while others affect Chrome generally (CVE-2026-106301, CVE-2026-106198, CVE-2026-106403).

Affected Versions

All eight vulnerabilities affect Google Chrome versions prior to 155.0.8059.39.

Fixes and Mitigation

Google has released Chrome version 155.0.8059.39, which resolves all eight vulnerabilities described in this briefing. Chrome's built-in auto-update mechanism will deliver this update automatically on most installations; users can also trigger an immediate check via the browser's 'About Chrome' settings page.

Recommended Action

Verify that Chrome has updated to version 155.0.8059.39 or later across all managed desktop, Android, and iOS installations. For enterprise environments, confirm that update policies allow the Stable Channel release to propagate promptly, since several of these issues affect privilege and isolation boundaries that are relevant to defense-in-depth strategies.

PatchBriefing score

5.6 / 10 · Medium

Official CVSS: 8.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Why this score

The patchwire score (5.6 for the six highest-severity entries, 5.3 for the remaining two) reflects a composite calculation: each vulnerability has a notable CVSS base score (ranging from 7.3 to 8.4), contributing the largest share of the score. Additional minor contributions come from the vulnerabilities being remotely reachable without authentication (unauthenticated_remote) for most entries, Chrome's very large install base (product_popularity), and in some cases the absence of required user interaction. None of the vulnerabilities are flagged as known exploited or associated with public exploit code, and EPSS data was not available for any of them, which keeps the overall scores in the medium range rather than critical.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has released Chrome version 155.0.8059.39, which resolves all eight vulnerabilities described in this briefing. Chrome's built-in auto-update mechanism will deliver this update automatically on most installations; users can also trigger an immediate check via the browser's 'About Chrome' settings page.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome 155 Patches Eight Medium-to-High Severity Vulnerabilities
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email