Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 Browsers CVE-2026-106252 CVE-2026-106350 CVE-2026-106421 CVE-2026-106207

Google Chrome Stable Update Fixes Eight Vulnerabilities, Including Critical-Severity Use-After-Free

Google released a Chrome Stable channel update fixing eight vulnerabilities, including a Chromium-rated Critical use-after-free bug. All issues are addressed in version 155.0.8059.39.

AI summary

Google has published a Stable channel update for Chrome on desktop that addresses eight separate vulnerabilities identified in Chromium components. The fixes are included in Chrome version 155.0.8059.39. The vulnerabilities range in Chromium-assigned severity from Low to Critical and involve several different Chrome components, including V8, PDF handling, Autofill, and font processing. According to the vendor's release notes, all eight issues are resolved in this update.

What happened

Google released a Stable channel update for Chrome on desktop that fixes eight distinct vulnerabilities across multiple Chrome components. The issues include use-after-free bugs (CVE-2026-106421, CVE-2026-106315, CVE-2026-106347), race conditions (CVE-2026-106207, CVE-2026-106255), incorrect authorization issues (CVE-2026-106350, CVE-2026-106212), and an incorrect comparison bug in font handling (CVE-2026-106252). All eight vulnerabilities are described as exploitable via a crafted HTML page.

Technical causes

The vulnerabilities stem from several distinct root causes across different Chrome components. Three are use-after-free issues (CWE-416) affecting the PDF component, Modularization, and Track functionality. Two are race conditions (CWE-367 and CWE-362) in the V8 JavaScript engine. Two involve incorrect authorization (CWE-863) in the Browser and Autofill components, which could allow a remote attacker to obtain sensitive information. The remaining issue is an incorrect comparison (CWE-697) in font handling. Each vulnerability requires a crafted HTML page to be processed by the browser; the Autofill-related issue additionally notes a social engineering element.

Why it matters

Several of these vulnerabilities, including the use-after-free and race condition issues, could allow a remote attacker to execute arbitrary code inside Chrome's sandbox simply by getting a user to visit a crafted HTML page or interact with such content. While Chromium assigns differing internal severity ratings to each issue (ranging from Low to Critical), all eight carry the same CVSS base score of 8.8 in this fact package, reflecting high potential impact on confidentiality, integrity, and availability if successfully exploited.

Who is affected

Any user running a version of Google Chrome on desktop prior to 155.0.8059.39 is potentially affected. Chrome is one of the most widely used web browsers globally, meaning the pool of potentially affected systems is very large.

Affected and fixed versions

The fact package does not specify a lower bound for affected Chrome versions; all eight advisories simply state that versions prior to 155.0.8059.39 are affected. Chrome 155.0.8059.39 contains the fix for all eight vulnerabilities listed in this briefing.

Fixes and mitigation

Google has released Chrome 155.0.8059.39 for desktop, which includes fixes for all eight vulnerabilities covered in this briefing. Chrome typically updates automatically in the background; users and administrators should confirm the update has been applied rather than assume it has.

Recommended action

Verify that Chrome is running version 155.0.8059.39 or later by checking the browser's About page, which will trigger an update check if one has not already occurred. Restart the browser after updating to ensure the fix is applied. Organizations managing Chrome deployments via enterprise policy should confirm that the update has been pushed to all managed endpoints.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Why this score

All eight vulnerabilities in this update carry a CVSS base score of 8.8 (CVSS:3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), reflecting network-exploitable issues with low attack complexity, no privileges required, but requiring user interaction, with high impact on confidentiality, integrity, and availability. The computed patchwire_score of 5.9 reflects this CVSS base score combined with the fact that these are unauthenticated remote issues on an extremely widely deployed product (Chrome), offset by the absence of known exploitation, no public exploit code, and no missing fix. None of these vulnerabilities are listed as known exploited or as having public exploit code at this time.

Affected versions

≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched
≥ 155.0.8059.39
patched

Reported fixes

Google has released Chrome 155.0.8059.39 for desktop, which includes fixes for all eight vulnerabilities covered in this briefing. Chrome typically updates automatically in the background; users and administrators should confirm the update has been applied rather than assume it has.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Eight Vulnerabilities, Including Critical-Severity Use-After-Free
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email