www.malwarebytes.com 7 Oct 2026, 10:25 UTC

Google Fixes Critical Chrome Flaws That Could Enable Remote Code Execution

Google Fixes Critical Chrome Flaws That Could Enable Remote Code Execution
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

GOOGLE has released updates for Chrome and ChromeOS to address a set of significant security flaws. On 6 October 2026, Google issued a Stable Channel Update for Desktop, bringing Chrome to version 155.0.8059.39 for Linux and 154.0.8037.39/.40 for Windows and Mac, with the update including 247 security fixes, of which four are rated Critical. A separate Android update, version 155.0.8059.39, was released on the same day for a small portion of users, expected to improve stability and performance.

The article details three high‑impact vulnerabilities that have been fixed. CVE-2026-106197 is a use‑after‑free flaw in the Browser module, rated critical, which could allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. CVE-2026-106358 is another use‑after‑free issue, this time in Navigation, also rated critical and potentially enabling remote code execution from attacker‑controlled pages.

CVE-2026-106240 is a type confusion vulnerability in V8, rated High, with the possibility of remote code execution inside the sandbox via crafted HTML. The piece notes that exploitation would typically occur through malicious web content and may enable code execution on the underlying system outside the browser sandbox.

For users, the recommended practical response is to update Chrome promptly (automatic updates are easiest, though manual updates via About Google Chrome are described), and to update ChromeOS by following the standard Device Update flow. The article also reinforces the benefits of Chrome’s updated security posture and the importance of staying current with browser and OS patches.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline