Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-106323: Chrome on iOS before 155 can run malicious web page code
CVE-2026-106323 · published 4 days ago
Summary
Google Chrome for iOS versions earlier than 155.0.8059.39 may let a specially crafted web page execute code on the device without permission. This could let an attacker take actions outside the browser’s normal safety boundaries. Update Chrome on iOS to the latest version to eliminate the risk.
What to do
- Update google chrome to version 155.0.8059.39 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | chrome | < 155.0.8059.39 | |
| Debian:12 | debian | chromium | All versions |
Original advisory text
DEBIAN-CVE-2026-106323
Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.6
Critical
Type
CWE-862Missing Authorization
Timeline
Published6 Oct 2026
Updated8 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta