CVE-2026-106382
CVSS 9.6 CRITICAL: use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Vulnerabilità · 8 ore fa
Google ha rilasciato Chrome 155 per correggere 247 vulnerabilità, tra cui quattro use-after-free critiche tracciate come CVE-2026-106382, CVE-2026-106197, CVE-2026-106358 e CVE-2026-106347. Le correzioni stanno arrivando nelle versioni 155.0.8059.39/.40 per Windows e macOS, e 155.0.8059.39 per Linux.
Le quattro falle riguardano componenti del browser e possono permettere l’esecuzione di codice partendo da una pagina costruita ad arte, senza bisogno di privilegi locali. Google non segnala sfruttamento in the wild. Nello stesso giro, alcuni bug sono stati trovati con AI e l’azienda ha indicato che non riconoscerà tutti i bounty, segno di un ciclo di ricerca che sta già cambiando i criteri di merito.
Per chi gestisce Chrome su Windows, macOS e Linux, la notizia resta un patch cycle ampio ma lineare: il rischio reale è l’esposizione di chi visita contenuti ostili prima dell’aggiornamento. La dinamica della ricerca automatizzata, invece, pesa sul futuro degli incentivi ai ricercatori più della superficie d’attacco di oggi.
CVSS 9.6 CRITICAL: use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVSS 9.6 CRITICAL: use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVSS 9.6 CRITICAL: use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVSS 8.8 HIGH: use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
2 fonti che coprono questa storia
Chrome 155 Update Patches 247 Vulnerabilities
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.
CVE-2026-106269: Google Chrome
Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
CVE-2026-106234: Google Chrome
Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension.
CVE-2026-106355: Google Chrome
Missing authorization in Media in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page.
CVE-2026-106272: Google Chrome
UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via crafted network traffic.
CVE-2026-106345: Google Chrome
Use of released resource in Session in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page.
CVE-2026-106310: Google Chrome
Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page.
CVE-2026-106251: Google Chrome
UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic.
CVE-2026-106236: Google Chrome
UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic.
CVE-2026-106334: Google Chrome
Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page.
CVE-2026-106294: Google Chrome
Incomplete cleanup in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic.
CVE-2026-106390: Google Chrome
Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page.
Part of the PlainSec briefing for 2026-10-07