Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-106414: Chrome on iOS before 155.0.8059.39 can run malicious code

CVE-2026-106414 · published 4 days ago
Summary

The mobile version of Google Chrome for iOS and the Debian build of Chromium older than version 155.0.8059.39 may allow a specially crafted web page to run code outside its normal restrictions. An attacker would have to persuade a user to open a malicious page, but doing so could let the code take actions beyond the browser's safety limits. Update Chrome and Chromium to the latest releases to eliminate the risk.

What to do
  • Update google chrome to version 155.0.8059.39 or later.
Affected software
Ecosystem VendorProductAffected versions
– google chrome < 155.0.8059.39
Debian:12 debian chromium All versions
Original advisory text
DEBIAN-CVE-2026-106414
Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-20Improper Input Validation
Timeline
Published6 Oct 2026
Updated8 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-106414 · MITRE
Track software like this
Free during beta