Medium · 5.9 Browsers CVE-2026-106334 CVE-2026-106204 CVE-2026-106269 CVE-2026-106387
Google Chrome Stable Update Fixes Five Vulnerabilities, Including Two Use-After-Free Sandbox Escapes
Google released a Chrome Stable channel update addressing five vulnerabilities, including two high-severity use-after-free flaws in the Media and PDF components that could allow sandboxed code execution via crafted content. All issues are fixed in version 155.0.8059.39.
AI summary
Google has published a Stable Channel update for Google Chrome on desktop, resolving five distinct vulnerabilities disclosed under CVE-2026-106334, CVE-2026-106204, CVE-2026-106269, CVE-2026-106387, and CVE-2026-106318. The update is available in version 155.0.8059.39. The issues span use-after-free memory corruption, an information leak, and a missing authorization check, with Chromium-assigned severities ranging from Low to High. Google has not reported any of these vulnerabilities as being exploited in the wild.
What Happened
Google released a Stable Channel update for Chrome on desktop that fixes five separate vulnerabilities. Two are use-after-free flaws rated High severity by Chromium: one in the Media component (CVE-2026-106318), reachable via a crafted HTML page, and one in the PDF component (CVE-2026-106204), reachable via a crafted PDF file. Both could allow a remote attacker to execute arbitrary code inside Chrome's sandbox. A third use-after-free in the CSS component (CVE-2026-106269), rated Low severity, could similarly allow sandboxed code execution via a crafted HTML page. Additionally, an information leak in the Payments component (CVE-2026-106334, Low severity) could expose sensitive information via a crafted HTML page when combined with social engineering, and a missing authorization issue affecting Chrome Mobile on iOS (CVE-2026-106387, Medium severity) could similarly expose sensitive information through social engineering and a crafted HTML page.
Technical Cause
Three of the five issues (CVE-2026-106318, CVE-2026-106204, CVE-2026-106269) are classified as use-after-free (CWE-416), a memory safety defect where a program continues to reference memory after it has been freed, which can be abused to achieve arbitrary code execution inside the browser sandbox. CVE-2026-106334 is classified as an information leak (CWE-200), where sensitive data is exposed to an unauthorized actor. CVE-2026-106387 is classified as a missing authorization check (CWE-862), where expected access controls were not enforced, allowing exposure of information on the iOS Chrome Mobile platform.
Why It Matters
The two High-severity use-after-free vulnerabilities (CVE-2026-106318 and CVE-2026-106204) are the most significant in this batch: successful exploitation could let an attacker run arbitrary code inside Chrome's sandbox simply by getting a user to view a crafted HTML page or open a crafted PDF file. While sandbox containment limits the immediate impact, code execution vulnerabilities of this kind are frequently chained with sandbox-escape bugs in real-world attacks. The remaining issues (information leak and missing authorization) carry lower Chromium-assigned severities but still involve exposure of sensitive information and generally require some form of social engineering to succeed.
Who Is Affected
All users running Google Chrome on desktop prior to version 155.0.8059.39 are affected by CVE-2026-106334, CVE-2026-106204, CVE-2026-106269, and CVE-2026-106318. CVE-2026-106387 specifically affects Google Chrome Mobile on iOS prior to the same fixed version.
Affected Versions
Google Chrome versions prior to 155.0.8059.39 are affected across all five vulnerabilities described in this update.
Fixes and Mitigation
Google has released version 155.0.8059.39 of Chrome for desktop, which addresses all five vulnerabilities covered in this advisory. Chrome typically updates automatically; users and administrators should verify that the browser has updated to this version or later via the built-in update mechanism (chrome://settings/help).
Recommended Action
Confirm that Google Chrome has updated to version 155.0.8059.39 or later on all desktop and iOS devices in your environment. Restart the browser if an update is pending, as Chrome updates are not applied until relaunch. Organizations managing Chrome deployments via enterprise policy should verify that the update has propagated across managed fleets.
PatchBriefing score
5.9 / 10 · Medium
Official CVSS: 8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Why this score
The patchwire_score of 5.9 reflects a CVSS base score of 8.8 for each listed vulnerability, contributing the bulk of the score, combined with a small addition for unauthenticated remote attack vectors and Chrome's very large installed user base. No known exploitation, public exploit code, or EPSS data were available to elevate the score further, and the presence of a vendor fix prevented any additional contribution for unpatched status. All five vulnerabilities require user interaction (e.g., visiting a crafted page or opening a crafted file), which moderates real-world risk compared to zero-click issues.
Affected versions
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
- ≥ 155.0.8059.39
- patched
Reported fixes
Google has released version 155.0.8059.39 of Chrome for desktop, which addresses all five vulnerabilities covered in this advisory. Chrome typically updates automatically; users and administrators should verify that the browser has updated to this version or later via the built-in update mechanism (chrome://settings/help).
How this was built
6 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email