Vulnerability record

CVE-2026-106327

Exploitation: No known exploitation

Patch status

Official fix available since

Apply the vendor's update to every affected system. Check the fixed-in versions below where known.

Basis: Google Chrome Releases vendor advisory

Description

Incorrect authorization in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

No developments recorded for CVE-2026-106327 in the last 30 days.

Coverage

Severity: CriticalAction: Patch

Stable Channel Update for Desktop

Patch

Apply the vendor's security update for Windows, Chrome, Linux and Claude.

References