Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.4 Browsers CVE-2026-106281 CVE-2026-106329 CVE-2026-106358 CVE-2026-106382

Google Chrome Stable Update Fixes Eight High-Severity Vulnerabilities

Google released a Chrome Stable channel update addressing eight vulnerabilities, including several use-after-free and authorization flaws that could allow remote code execution outside the browser sandbox via crafted HTML pages. Update to version 155.0.8059.39.

AI summary

Google has published a Stable Channel update for Chrome on desktop, addressing eight distinct vulnerabilities disclosed under CVE-2026-106281, CVE-2026-106329, CVE-2026-106358, CVE-2026-106382, CVE-2026-106241, CVE-2026-106414, CVE-2026-106401, and CVE-2026-106298. The flaws span multiple Chrome components, including Tint, FileSystem, Navigation, Chromecast, Search (Android), Mobile (iOS), Media, and Chrome Tabs (Mac). All are fixed in Chrome version 155.0.8059.39, released via the vendor's official Stable Channel announcement. None of the issues are currently known to be exploited in the wild.

What happened

Google published a Chrome Stable Channel update bundling fixes for eight separate vulnerabilities across different browser components: Tint (CVE-2026-106281), FileSystem (CVE-2026-106329), Navigation (CVE-2026-106358), Chromecast (CVE-2026-106382), Search on Android (CVE-2026-106241), Mobile on iOS (CVE-2026-106414), Media (CVE-2026-106401), and Chrome Tabs on Mac (CVE-2026-106298). Chromium's own severity ratings for these issues range from Medium to Critical. All advisories describe exploitation via a crafted HTML page.

Technical causes

The vulnerabilities stem from several distinct weaknesses: use-after-free conditions (CWE-416) in Tint, Navigation, Chromecast, and Chrome Tabs components (CVE-2026-106281, CVE-2026-106358, CVE-2026-106382, CVE-2026-106298); incorrect authorization (CWE-863) in FileSystem and Search (CVE-2026-106329, CVE-2026-106241); improper input validation (CWE-20) in the iOS Mobile component (CVE-2026-106414); and an out-of-bounds write (CWE-787) in Media (CVE-2026-106401). Each is described as potentially allowing a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page, with several requiring social engineering or user interaction to trigger.

Why it matters

Each of these eight CVEs carries a CVSS base score of 9.6, reflecting network-exploitable, low-complexity attack paths with high impact on confidentiality, integrity, and availability, and a scope change indicating potential sandbox escape. Several are rated Critical or High by Chromium's internal severity scale, meaning successful exploitation could allow code execution outside Chrome's security sandbox. Given Chrome's extremely large install base, unpatched installations represent a broad attack surface, even though no exploitation has been observed so far.

Who is affected

All users running Google Chrome on desktop prior to version 155.0.8059.39 are affected by the core set of vulnerabilities. Some issues are platform-specific: CVE-2026-106241 affects Chrome on Android, CVE-2026-106414 affects Chrome on iOS, and CVE-2026-106298 affects Chrome on Mac. Organizations managing Chrome deployments across desktop and mobile platforms should treat this as affecting their full fleet.

Affected versions

All versions of Google Chrome prior to 155.0.8059.39 are affected by one or more of these vulnerabilities. The fact package does not specify a lower bound for affected version ranges.

Fixes and mitigation

Google has released Chrome version 155.0.8059.39 for desktop, which resolves all eight vulnerabilities described in this briefing. The fix was announced via Google's official Chrome Releases (Stable) blog.

Recommended action

Update Google Chrome to version 155.0.8059.39 or later as soon as possible. Chrome typically updates automatically on relaunch; users and administrators should verify via chrome://settings/help and restart the browser to apply the update. Enterprises managing Chrome through policy should prioritize rollout given the number and severity of fixed issues.

PatchBriefing score

6.4 / 10 · Medium

Official CVSS: 9.6

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

All eight vulnerabilities carry a CVSS base score of 9.6, driven by network attack vector, low attack complexity, no privileges required, and high impact to confidentiality, integrity, and availability, combined with a scope change suggesting possible sandbox escape. The computed PatchBriefing score of 6.4 reflects this high CVSS base score plus modest additions for unauthenticated remote exploitability and Chrome's very large install base, offset by the absence of known exploitation, public exploit code, or EPSS data. No active exploitation has been reported for any of these CVEs.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has released Chrome version 155.0.8059.39 for desktop, which resolves all eight vulnerabilities described in this briefing. The fix was announced via Google's official Chrome Releases (Stable) blog.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Eight High-Severity Vulnerabilities
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email