Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-106358: Chrome/Chromium on Debian can run code from malicious page

CVE-2026-106358 · published 4 days ago
Summary

A flaw in the web navigation component of Chrome and Chromium on Debian lets a specially crafted web page break out of the browser's safety barrier and run code on the computer. This could let an attacker take control of the system without the user’s knowledge. Install the latest browser updates from your Debian package manager as soon as they are available to close the gap.

What to do
  • Update google chrome to version 155.0.8059.39 or later.
Affected software
Ecosystem VendorProductAffected versions
– google chrome < 155.0.8059.39
Debian:12 debian chromium All versions
Original advisory text
DEBIAN-CVE-2026-106358
Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-416Use After Free
Timeline
Published6 Oct 2026
Updated11 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-106358 · MITRE
Track software like this
Free during beta