Chromium: 25 Vulnerabilities Patched in Single October 6, 2026 Disclosure
Key findings • 25 vulnerabilities in Chromium disclosed on October 6, 2026, fixed in Chrome 155.0.8059.39. • Batch includes critical and high-severity flaws like use-after-free and race condi…

Key findings
- 25 vulnerabilities in Chromium disclosed on October 6, 2026, fixed in Chrome 155.0.8059.39.
- Batch includes critical and high-severity flaws like use-after-free and race conditions.
- Vulnerabilities affect core components including Media, Fonts, and Sandbox.
- Attack vectors range from crafted HTML to social engineering.
- Urgent update to Chrome 155.0.8059.39 recommended for all users.
On October 6, 2026, Google released Chrome version 155.0.8059.39, addressing a batch of 25 vulnerabilities disclosed on the same day. This significant update includes fixes for several high and critical severity flaws, with the potential for remote attackers to execute arbitrary code, bypass security restrictions, and leak sensitive information. The vulnerabilities affected various components including ANGLE, Media, Mobile, and Extensions, with attack vectors including crafted HTML, malicious extensions, and social engineering. All users are urged to update to version 155.0.8059.39 for security.
The disclosed vulnerabilities can be grouped by their impact and affected components:
Use After Free Vulnerabilities
A significant portion of the batch consists of "use after free" vulnerabilities, which can lead to arbitrary code execution. These include:
CVE-2026-106423in Media, allowing remote attackers to execute arbitrary code inside the sandbox.CVE-2026-106411in Parser, also allowing remote attackers to execute arbitrary code inside the sandbox.CVE-2026-106393in Storage, enabling remote attackers who compromised the renderer process to execute arbitrary code outside the sandbox.CVE-2026-106383andCVE-2026-106335in Media, allowing remote attackers to execute arbitrary code inside the sandbox.CVE-2026-106373in Fonts on Windows, allowing remote attackers to execute arbitrary code inside the sandbox.CVE-2026-106358in Navigation, a critical vulnerability allowing remote attackers to execute arbitrary code outside the sandbox.CVE-2026-106318in Media, allowing remote attackers to execute arbitrary code inside the sandbox.
Race Conditions and Out-of-Bounds Writes
Race conditions and out-of-bounds writes represent other critical attack vectors:
CVE-2026-106426andCVE-2026-106377in Fonts, both race conditions that could allow remote attackers to execute arbitrary code outside the sandbox.CVE-2026-106401in Media, an out-of-bounds write that could allow remote attackers to execute arbitrary code outside the sandbox.
Incorrect Authorization and Protection Mechanism Failures
Several vulnerabilities stem from incorrect authorization or failures in protection mechanisms, potentially leading to information leaks or bypasses of security policies:
CVE-2026-106408in Mobile on iOS, a protection mechanism failure that could allow remote attackers to bypass web origin policy.CVE-2026-106404in FontAccess, an incorrect authorization flaw that could allow remote attackers to bypass system access restrictions.CVE-2026-106403in Accessibility, an incorrect authorization flaw that could allow remote attackers to bypass site isolation.CVE-2026-106398in Media, an incorrect authorization flaw that could allow remote attackers to leak cross-origin data.CVE-2026-106369in Translate, a missing authorization flaw that could allow remote attackers to bypass site isolation.CVE-2026-106355in Media on Windows, a missing authorization flaw that could allow remote attackers to obtain sensitive information.CVE-2026-106327in Core, an incorrect authorization flaw that could allow remote attackers to bypass system access restrictions.
Other Vulnerabilities
The batch also includes vulnerabilities such as code injection, integer overflows, observable discrepancies, and open redirects:
CVE-2026-106416in Extensions, a code injection flaw that could allow remote attackers to spoof UI elements via social engineering.CVE-2026-106336in Paint, an observable discrepancy that could allow remote attackers to leak cross-origin data.CVE-2026-106332in Compositing, an integer overflow that could allow remote attackers to obtain cross-origin data.CVE-2026-106322in AppManifest, an open redirect vulnerability that could allow remote attackers to bypass web origin policy via social engineering.CVE-2026-106333in Input, an incorrect authorization flaw that could allow remote attackers to spoof UI elements via social engineering.CVE-2026-106360in Payments, an information leak vulnerability that could allow remote attackers to obtain cross-origin data.
The disclosure of these 25 vulnerabilities in a single batch highlights the importance of timely patching and updates for web browsers. Users are strongly advised to ensure their Chrome browser is updated to version 155.0.8059.39 or later to mitigate the risks associated with these security flaws. The variety of vulnerabilities, ranging from memory corruption issues to authorization bypasses, underscores the complex security landscape of modern web browsers.
N1 https://portal.vyprsec.ai/articles/google-chrome-25-vulnerabilities-patched-in-single-october-2026-disclosure