Vulnerability record

CVE-2026-106197

Severity: CriticalExploitation: No known exploitation

Patch status

Official fix available since

Apply the vendor's update to every affected system. Check the fixed-in versions below where known.

Basis: Google Chrome Releases vendor advisory

Description

Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-106197 scored CVSS 9.6

    Basis: NIST National Vulnerability Database

Coverage

Severity: CriticalAction: Patch

Stable Channel Update for Desktop

Patch

Apply the vendor's security update for Windows, Chrome, Linux and Claude.

References