VYPR
patchPublished Oct 6, 2026· Updated Oct 7, 2026· 1 source

Google Chrome: 25 Vulnerabilities Patched in Single October 2026 Disclosure

Key findings • Google Chrome version 155.0.8059.39 patched 25 vulnerabilities disclosed on October 6, 2026. • The batch includes critical and high-severity flaws enabling arbitrary code execu…

Key findings

  • Google Chrome version 155.0.8059.39 patched 25 vulnerabilities disclosed on October 6, 2026.
  • The batch includes critical and high-severity flaws enabling arbitrary code execution and sandbox escapes.
  • Vulnerabilities affected various components including ANGLE, Media, Mobile, and Extensions.
  • Attack vectors included crafted HTML, malicious extensions, and social engineering.
  • All users are urged to update to version 155.0.8059.39 for security.

On October 6, 2026, Google released Chrome version 155.0.8059.39, addressing a batch of 25 vulnerabilities disclosed on the same day. This significant update includes fixes for several high and critical severity flaws, with the potential for remote attackers to execute arbitrary code, bypass security restrictions, and leak sensitive information. The vulnerabilities span various components of Chrome, including ANGLE, Media, Mobile, and Extensions, and were introduced via crafted HTML pages, extensions, or network traffic.

Several critical and high-severity vulnerabilities were patched in this release. CVE-2026-106414, a medium-severity improper input validation flaw in the Mobile component on iOS, carried a critical CVSSv3 score of 9.6 due to its potential to allow arbitrary code execution outside the sandbox when combined with social engineering. Similarly, CVE-2026-106419, a high-severity use-after-free vulnerability in ANGLE on Android, also rated critical with a CVSSv3 score of 9.6, could lead to arbitrary code execution outside the sandbox. Other high-severity issues include CVE-2026-106426 (race condition in Fonts), CVE-2026-106423 (use-after-free in Media), CVE-2026-106411 (use-after-free in Parser), and CVE-2026-106412 (race condition in Core on Mac), all carrying CVSSv3 scores of 8.3 or 8.8 and posing risks of arbitrary code execution.

The batch also includes numerous medium-severity vulnerabilities. These range from missing authorization and incorrect authorization flaws in components like BrowserTag, Network, Permissions, GetUserMedia, FontAccess, and Accessibility, to information leaks in Audio and Enterprise, and UI spoofing possibilities via code injection in Extensions or incorrect calculations in API. CVE-2026-106405, a race condition in CustomTabs on Android, allowed a local attacker to bypass web origin policy.

The vulnerabilities were introduced through various attack vectors. Remote attackers could exploit these flaws by presenting crafted HTML pages, malicious Chrome extensions, or specially crafted network traffic. Social engineering was also a factor in several vulnerabilities, enabling attackers to trick users into actions that led to exploitation, such as spoofing UI elements or bypassing security policies. The affected versions of Chrome are all prior to 155.0.8059.39.

Google has addressed all these vulnerabilities in the release of Chrome 155.0.8059.39. Users are strongly advised to update their Chrome browsers to this latest version to protect themselves from these security risks. The swift patching of such a large batch of vulnerabilities highlights Google's commitment to Chrome security, though the sheer number and severity of the flaws underscore the ongoing challenges in securing complex web browsers.

This coordinated disclosure of 25 vulnerabilities on a single day emphasizes the importance of timely patching for all users. The variety of vulnerability types and affected components indicates a broad range of potential risks that were mitigated by this single update. Users should remain vigilant and ensure their browsers are consistently updated to the latest stable version.

The vulnerabilities patched include:

This comprehensive update ensures a more secure browsing experience for millions of Google Chrome users worldwide.

CVE-2026-106427, CVE-2026-106426, CVE-2026-106425, CVE-2026-106424, CVE-2026-106423, CVE-2026-106422, CVE-2026-106420, CVE-2026-106419, CVE-2026-106418, CVE-2026-106416, CVE-2026-106415, CVE-2026-106414, CVE-2026-106413, CVE-2026-106412, CVE-2026-106411, CVE-2026-106410, CVE-2026-106409, CVE-2026-106408, CVE-2026-106407, CVE-2026-106406, CVE-2026-106405, CVE-2026-106404, CVE-2026-106403, CVE-2026-106402, CVE-2026-106401

Synthesized by Vypr AI