Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-106417: Chrome and Chromium may run code from malicious page
CVE-2026-106417 · published 4 days ago
Summary
A flaw in the media handling code of Google Chrome and Debian's Chromium can let a remote attacker cause the browser to run code outside its normal safety walls by sending a specially crafted web page. This could let the attacker take actions on the affected computer. Update Chrome and the Debian Chromium package to the latest version that includes the fix, and apply regular security updates.
What to do
- Update google chrome to version 155.0.8059.39 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | chrome | < 155.0.8059.39 | |
| Debian:12 | debian | chromium | All versions |
Original advisory text
DEBIAN-CVE-2026-106417
Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.6
Critical
Type
CWE-190Integer Overflow
Timeline
Published6 Oct 2026
Updated8 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta