Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-106195: Chrome/Chromium on Mac can be remotely bypassed

CVE-2026-106195 · published 3 days ago
Summary

Google Chrome on macOS and the Debian Chromium package versions earlier than 155.0.8059.39 may let a remote attacker send specially crafted network data to get around normal system access controls. This could let an attacker perform actions they should not be able to. Update Chrome or Chromium to version 155.0.8059.39 or newer to close the issue.

What to do
  • Update google chrome to version 155.0.8059.39 or later.
Affected software
Ecosystem VendorProductAffected versions
– google chrome < 155.0.8059.39
Debian:12 debian chromium All versions
Original advisory text
DEBIAN-CVE-2026-106195
Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-863Incorrect Authorization
Timeline
Published6 Oct 2026
Updated10 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-106195 · MITRE
Track software like this
Free during beta