T
Threats
Google Chrome Use-After-Free Vulnerabilities
Overview
Product: Google Chrome
CVEs: CVE-2026-106197, CVE-2026-106358, CVE-2026-106382, CVE-2026-106211, CVE-2026-106227, CVE-2026-106281, CVE-2026-106419, CVE-2026-106234
Overall Severity: Critical
Publication Date: 6 October 2026
CVE Record Update Date: 7 October 2026
Prioritise browser updates across managed endpoints and Android devices. This advisory covers the eight supplied CVEs, not every vulnerability in the Chrome 155 release.
Severity context: Google's Chromium ratings are Critical for three CVEs, High for four and Low for one. CISA's enrichment of the CVE records assigns all eight a CVSS v3.1 score of 9.6, Critical. These are different assessment systems. The breakdown follows the vendor's severity ordering and identifies the CISA score separately.
Affected Versions
Google Chrome - Browser, Navigation, Chromecast, TabStrip, Core, Tint and Network
Applies to the seven CVEs below, excluding the Android-specific ANGLE entry.
Affected: Google Chrome versions earlier than 155.0.8059.39, as stated in Google's individual CVE descriptions.
Fixed: Windows and macOS Stable 155.0.8059.39 or 155.0.8059.40; Linux Stable 155.0.8059.39. The corresponding Android Stable release is 155.0.8059.39 and includes the same security fixes unless otherwise noted.
Not affected: No additional unaffected version ranges or configurations are explicitly identified in the reviewed release notices or CVE records.
Source: Google Chrome desktop Stable release, 6 October 2026 and Google Chrome Android Stable release, 6 October 2026.
Individual affected-version sources:
Google Chrome on Android - ANGLE, CVE-2026-106419
Affected: Google Chrome on Android versions earlier than 155.0.8059.39.
Fixed: Chrome for Android Stable 155.0.8059.39.
Not affected: The CVE description specifically scopes this flaw to Android. It does not publish a separate list of unaffected configurations.
Source: Google CVE record for CVE-2026-106419 and Google Chrome Android Stable release, 6 October 2026.
Vulnerability Breakdown
CVE-2026-106197 - Use-after-free in Browser
Severity: Critical, Chromium vendor rating.
CVSS: 9.6, Critical, CVSS v3.1, CISA enrichment.
Description: A use-after-free flaw in Browser allows a remote attacker to execute arbitrary code outside the sandbox through a crafted HTML page.
Impact: Arbitrary code execution outside Chrome's sandbox.
Conditions: A vulnerable browser processes the crafted HTML page. CISA's scoring indicates required user interaction and no attacker privileges.
CVE-2026-106358 - Use-after-free in Navigation
Severity: Critical, Chromium vendor rating.
CVSS: 9.6, Critical, CVSS v3.1, CISA enrichment.
Description: A use-after-free flaw in Navigation allows a remote attacker to execute arbitrary code outside the sandbox through a crafted HTML page.
Impact: Arbitrary code execution outside Chrome's sandbox.
Conditions: A vulnerable browser processes the crafted HTML page. CISA's scoring indicates required user interaction and no attacker privileges.
CVE-2026-106382 - Use-after-free in Chromecast
Severity: Critical, Chromium vendor rating.
CVSS: 9.6, Critical, CVSS v3.1, CISA enrichment.
Description: A use-after-free flaw in Chrome's Chromecast component allows a remote attacker to execute arbitrary code outside the sandbox through a crafted HTML page.
Impact: Arbitrary code execution outside Chrome's sandbox. This entry concerns the Chrome component, not a separately established Chromecast device vulnerability.
Conditions: A vulnerable browser processes the crafted HTML page. CISA's scoring indicates required user interaction and no attacker privileges.
CVE-2026-106211 - Use-after-free in TabStrip
Severity: High, Chromium vendor rating.
CVSS: 9.6, Critical, CVSS v3.1, CISA enrichment.
Description: A use-after-free flaw in TabStrip may allow a remote attacker using social engineering to execute arbitrary code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome's sandbox.
Conditions: Social engineering and a crafted HTML page. CISA's scoring indicates required user interaction and no attacker privileges.
CVE-2026-106227 - Use-after-free in Core
Severity: High, Chromium vendor rating.
CVSS: 9.6, Critical, CVSS v3.1, CISA enrichment.
Description: A use-after-free flaw in Core allows a remote attacker to execute arbitrary code outside the sandbox through a crafted HTML page.
Impact: Arbitrary code execution outside Chrome's sandbox.
Conditions: A vulnerable browser processes the crafted HTML page. CISA's scoring indicates required user interaction and no attacker privileges.
CVE-2026-106281 - Use-after-free in Tint
Severity: High, Chromium vendor rating.
CVSS: 9.6, Critical, CVSS v3.1, CISA enrichment.
Description: Google's CVE record describes a Tint use-after-free flaw that may allow arbitrary code execution outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome's sandbox, as described in the CVE record.
Conditions: Crafted HTML processed by a vulnerable browser; CISA's scoring indicates required user interaction and no attacker privileges.
Notes: The public issue discussion reports reproduction in GCC/AddressSanitizer builds and states that the issue was not demonstrated in Chrome. This narrower reproduction evidence is not an explicit exemption from Google's published Chrome update guidance.
Source: Google CVE description and CISA assessment and Chromium Tint issue and fix discussion.
CVE-2026-106419 - Use-after-free in ANGLE on Android
Severity: High, Chromium vendor rating.
CVSS: 9.6, Critical, CVSS v3.1, CISA enrichment.
Description: A use-after-free flaw in ANGLE in Chrome on Android allows a remote attacker to execute arbitrary code outside the sandbox through a crafted HTML page.
Impact: Arbitrary code execution outside Chrome's sandbox on Android.
Conditions: Vulnerable Chrome on Android processes the crafted HTML page. CISA's scoring indicates required user interaction and no attacker privileges.
CVE-2026-106234 - Use-after-free in Network
Severity: Low, Chromium vendor rating.
CVSS: 9.6, Critical, CVSS v3.1, CISA enrichment.
Description: A use-after-free flaw in Network may allow a remote attacker using social engineering to execute arbitrary code outside the sandbox through a crafted Chrome extension.
Impact: Potential arbitrary code execution outside Chrome's sandbox.
Conditions: Social engineering involving a crafted Chrome extension. CISA's scoring indicates required user interaction and no attacker privileges.
Mitigation
Apply the Google desktop Stable update: 155.0.8059.39 or 155.0.8059.40 on Windows and macOS, and 155.0.8059.39 on Linux.
Apply the Google Android Stable update: 155.0.8059.39, distributed through Google Play.
Google's notices describe a staged rollout. Confirm that each endpoint has received the applicable fixed release rather than assuming update availability means deployment is complete.
The reviewed vendor release notices do not specify a workaround for these CVEs. Do not substitute general account controls for the browser update.
Summary for IT Teams
Products: Google Chrome on Windows, macOS, Linux and Android, with CVE-2026-106419 specifically scoped to Android.
Threat Level: Critical overall. Chromium rates the supplied flaws as three Critical, four High and one Low; CISA assigns each a CVSS v3.1 score of 9.6.
Action Required: Deploy the applicable fixed Stable release and verify installation across the environment.
Exploitation Status: Google's reviewed release notices do not report active exploitation of these eight CVEs. This is not proof that exploitation has not occurred.
Reference
Google notes that access to security issue details may remain restricted until most users receive fixes. Where issue details were restricted or unavailable, the public Google CVE records and release notices supplied the affected-version, impact and patch information.
Need Help?
If your organisation needs assistance assessing affected browsers or deploying updates, the Secure ISS SOC team is ready to help. Call 1300 769 460.

