Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-106419: Google Chrome and Debian Chromium can run malicious code
CVE-2026-106419 · published 4 days ago
Summary
A specially crafted web page can cause Google Chrome on Android and the Debian Chromium browser to execute unwanted code on the device. This could let an attacker take control of the app and potentially access other data. Update the browsers to the latest version as soon as possible.
What to do
- Update google chrome to version 155.0.8059.39 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | chrome | < 155.0.8059.39 | |
| Debian:12 | debian | chromium | All versions |
Original advisory text
DEBIAN-CVE-2026-106419
Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.6
Critical
Type
CWE-416Use After Free
Timeline
Published6 Oct 2026
Updated8 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta