Skip to content
Critical Vulnerabilities in Google Chrome Expose Users to Arbitrary Code Execution

Critical Vulnerabilities in Google Chrome Expose Users to Arbitrary Code Execution

First seen 7 Oct 2026, 15:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 17:29 UTC
  • •Multiple critical vulnerabilities in Google Chrome could allow arbitrary code execution.
  • •Affected versions include Chrome prior to 155.0.8059.39 for Windows, Mac, and Linux.
  • •No active exploitation has been reported, but users are urged to update their browsers.

Multiple critical vulnerabilities have been identified in Google Chrome, with the most severe allowing for arbitrary code execution. These vulnerabilities, including CVE-2026-106382 and CVE-2026-106197, affect various Chrome versions prior to 155.0.8059.39/.40 for Windows and Mac, and prior to 155.0.8059.39 for Linux. Exploitation could enable attackers to install programs, view, change, or delete data, or create accounts with full user rights. The vulnerabilities stem from various issues, including use-after-free errors and incorrect authorization. As of now, there are no reports of these vulnerabilities being in the wild. Users are advised to update their browsers to mitigate potential risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
CVE-2026-103630 published
A critical use-after-free vulnerability affecting MediaStream was disclosed, posing risks for Chrome users.
Crowe
2026-10-02
CVE-2026-103622 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-02
CVE-2026-103623 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-106382 published
A critical use-after-free vulnerability in Chrome was disclosed, allowing potential arbitrary code execution.
Cisecurity
2026-10-06
CVE-2026-106197 published
Another critical vulnerability in Chrome was published, also enabling arbitrary code execution through a use-after-free issue.
Cisecurity
2026-10-06
CVE-2026-106289 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-106385 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-106223 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-106402 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-106337 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track KillSec, Ikegami Tsushinki and CVE-2026-102322 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Chrome are affected?
Chrome versions prior to 155.0.8059.39 for Windows and Mac, and prior to 155.0.8059.39 for Linux are affected.
Are these vulnerabilities being exploited?
No, there are currently no reports of these vulnerabilities being actively exploited in the wild.
What should users do to protect themselves?
Users should update their Chrome browsers to the latest version to mitigate the risks associated with these vulnerabilities.