Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 Browsers CVE-2026-106371 CVE-2026-106200 CVE-2026-106278 CVE-2026-106346

Google Chrome Update Fixes Eight Vulnerabilities, Including Multiple Sandbox Escape Risks

Google has released Chrome 155.0.8059.39 for desktop, fixing eight vulnerabilities including several use-after-free and type confusion issues rated High or Medium severity by Chromium, plus two Android-specific information disclosure issues.

AI summary

Google has published a Stable Channel update for Chrome on desktop, addressing eight distinct vulnerabilities identified by Chromium's internal severity ratings as High, Medium, or Low. The fixes span several browser components, including the V8 JavaScript engine, media handling, DevTools, form controls, and password-related functionality on Android. All issues are addressed in Chrome version 155.0.8059.39. There is no indication in the available data that any of these vulnerabilities have been exploited in the wild.

What happened

Google released a Stable Channel update for Chrome on desktop that fixes eight separate vulnerabilities. Five are use-after-free, type confusion, or improper state validation issues in core browser components (Track, Select, DevTools, GarbageCollection, Media, and V8) that Chromium rates as High or Medium severity and that could allow a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. The remaining issues affect Chrome on Android and involve incorrect authorization and information leaks in the Transactions Platform and Passwords components, rated Low severity by Chromium, which could allow a remote attacker to obtain sensitive information via a crafted HTML page.

Technical cause

The vulnerabilities fall into several distinct categories. CVE-2026-106200 (Track), CVE-2026-106278 (Select), CVE-2026-106291 (GarbageCollection), and CVE-2026-106335 (Media) are use-after-free issues (CWE-416), where memory is accessed after it has been freed, potentially allowing an attacker to execute arbitrary code inside the sandbox. CVE-2026-106346 (DevTools) is an improper state validation issue (CWE-754) that could also enable code execution inside the sandbox. CVE-2026-106374 (V8) is a type confusion vulnerability (CWE-843) in Chrome's JavaScript engine, also potentially leading to sandboxed code execution. CVE-2026-106371 (Transactions Platform, Android) is an incorrect authorization issue (CWE-863), and CVE-2026-106256 (Passwords, Android) is an information leak (CWE-200); both could expose sensitive information to a remote attacker via a crafted HTML page. All issues share the same CVSS vector, indicating network-based attack access with low attack complexity, no privileges required, and user interaction required.

Why it matters

Several of these vulnerabilities could allow an attacker to execute arbitrary code within Chrome's sandbox simply by getting a user to visit a crafted web page, which Chromium's own severity ratings classify as High or Medium. While sandbox escape typically requires chaining with an additional vulnerability to fully compromise a system, successful exploitation of memory corruption bugs like use-after-free and type confusion can still lead to information disclosure, crashes, or further compromise. The two Android-specific issues could expose sensitive information, including password-related data, to an attacker without requiring high privileges.

Who is affected

All users running Google Chrome on desktop prior to version 155.0.8059.39 are affected by the core vulnerabilities. Two of the eight issues (CVE-2026-106371 and CVE-2026-106256) specifically affect Chrome on Android prior to the same fixed version.

Affected versions

All versions of Google Chrome prior to 155.0.8059.39 are affected. The fact package does not specify the exact starting version range for each vulnerability, so users on any version older than the fixed release should treat themselves as potentially affected.

Fixes and mitigation

Google has fixed all eight vulnerabilities in Chrome version 155.0.8059.39. Chrome typically applies this update automatically, but users and administrators should verify their browser version and restart Chrome to complete the update if it has not already been applied.

Recommended action

Verify that Chrome has updated to version 155.0.8059.39 or later by checking the browser's About page, and restart the browser to apply the update if needed. Organizations managing Chrome deployments via enterprise policy should confirm the update has propagated across managed devices, including Android devices affected by the two Android-specific issues.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Why this score

The PatchWire score of 5.9 reflects a CVSS base score of 8.8 across all eight vulnerabilities, combined with the fact that these are unauthenticated, remotely exploitable issues (contributing an additional 0.6) in a very widely used product (contributing 0.5). The score is moderated by the absence of known exploitation in the wild, no confirmed public exploit code, and no EPSS data, and by the fact that user interaction (visiting a crafted page) is required rather than a zero-click attack path. A fix is already available, which further limits urgency relative to unpatched flaws.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has fixed all eight vulnerabilities in Chrome version 155.0.8059.39. Chrome typically applies this update automatically, but users and administrators should verify their browser version and restart Chrome to complete the update if it has not already been applied.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Update Fixes Eight Vulnerabilities, Including Multiple Sandbox Escape Risks
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email