VYPR
Published Oct 6, 2026· Updated Oct 7, 2026· 1 source

Chromium: 25 Vulnerabilities Patched in Single October 6, 2026 Disclosure

Key findings • 25 vulnerabilities in Chromium disclosed on October 6, 2026, fixed in Chrome 155.0.8059.39. • Batch includes critical and high-severity flaws like use-after-free and race condi…

Key findings

  • 25 vulnerabilities in Chromium disclosed on October 6, 2026, fixed in Chrome 155.0.8059.39.
  • Batch includes critical and high-severity flaws like use-after-free and race conditions.
  • Vulnerabilities affect core components including Media, Fonts, and Sandbox.
  • Attack vectors range from crafted HTML to social engineering.
  • Urgent update to Chrome 155.0.8059.39 recommended for all users.

On October 6, 2026, Google released Chrome version 155.0.8059.39, addressing a batch of 25 vulnerabilities disclosed on the same day. This significant update includes fixes for several high and critical severity flaws, with the potential for remote attackers to execute arbitrary code, bypass security restrictions, and leak sensitive information. The vulnerabilities affected various components including ANGLE, Media, Mobile, and Extensions, with attack vectors including crafted HTML, malicious extensions, and social engineering. All users are urged to update to version 155.0.8059.39 for security.

The disclosed vulnerabilities can be grouped by their impact and affected components:

Use After Free Vulnerabilities

A significant portion of the batch consists of "use after free" vulnerabilities, which can lead to arbitrary code execution. These include:

  • CVE-2026-106423 in Media, allowing remote attackers to execute arbitrary code inside the sandbox.
  • CVE-2026-106411 in Parser, also allowing remote attackers to execute arbitrary code inside the sandbox.
  • CVE-2026-106393 in Storage, enabling remote attackers who compromised the renderer process to execute arbitrary code outside the sandbox.
  • CVE-2026-106383 and CVE-2026-106335 in Media, allowing remote attackers to execute arbitrary code inside the sandbox.
  • CVE-2026-106373 in Fonts on Windows, allowing remote attackers to execute arbitrary code inside the sandbox.
  • CVE-2026-106358 in Navigation, a critical vulnerability allowing remote attackers to execute arbitrary code outside the sandbox.
  • CVE-2026-106318 in Media, allowing remote attackers to execute arbitrary code inside the sandbox.

Race Conditions and Out-of-Bounds Writes

Race conditions and out-of-bounds writes represent other critical attack vectors:

  • CVE-2026-106426 and CVE-2026-106377 in Fonts, both race conditions that could allow remote attackers to execute arbitrary code outside the sandbox.
  • CVE-2026-106401 in Media, an out-of-bounds write that could allow remote attackers to execute arbitrary code outside the sandbox.

Incorrect Authorization and Protection Mechanism Failures

Several vulnerabilities stem from incorrect authorization or failures in protection mechanisms, potentially leading to information leaks or bypasses of security policies:

  • CVE-2026-106408 in Mobile on iOS, a protection mechanism failure that could allow remote attackers to bypass web origin policy.
  • CVE-2026-106404 in FontAccess, an incorrect authorization flaw that could allow remote attackers to bypass system access restrictions.
  • CVE-2026-106403 in Accessibility, an incorrect authorization flaw that could allow remote attackers to bypass site isolation.
  • CVE-2026-106398 in Media, an incorrect authorization flaw that could allow remote attackers to leak cross-origin data.
  • CVE-2026-106369 in Translate, a missing authorization flaw that could allow remote attackers to bypass site isolation.
  • CVE-2026-106355 in Media on Windows, a missing authorization flaw that could allow remote attackers to obtain sensitive information.
  • CVE-2026-106327 in Core, an incorrect authorization flaw that could allow remote attackers to bypass system access restrictions.

Other Vulnerabilities

The batch also includes vulnerabilities such as code injection, integer overflows, observable discrepancies, and open redirects:

  • CVE-2026-106416 in Extensions, a code injection flaw that could allow remote attackers to spoof UI elements via social engineering.
  • CVE-2026-106336 in Paint, an observable discrepancy that could allow remote attackers to leak cross-origin data.
  • CVE-2026-106332 in Compositing, an integer overflow that could allow remote attackers to obtain cross-origin data.
  • CVE-2026-106322 in AppManifest, an open redirect vulnerability that could allow remote attackers to bypass web origin policy via social engineering.
  • CVE-2026-106333 in Input, an incorrect authorization flaw that could allow remote attackers to spoof UI elements via social engineering.
  • CVE-2026-106360 in Payments, an information leak vulnerability that could allow remote attackers to obtain cross-origin data.

The disclosure of these 25 vulnerabilities in a single batch highlights the importance of timely patching and updates for web browsers. Users are strongly advised to ensure their Chrome browser is updated to version 155.0.8059.39 or later to mitigate the risks associated with these security flaws. The variety of vulnerabilities, ranging from memory corruption issues to authorization bypasses, underscores the complex security landscape of modern web browsers.

N1 https://portal.vyprsec.ai/articles/google-chrome-25-vulnerabilities-patched-in-single-october-2026-disclosure

Synthesized by Vypr AI