Description
Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Arbitrary code execution outside the sandbox
Action: Apply Patch
AI Analysis

Impact

An incorrect authorization check in the Search feature of Google Chrome on Android allows a remote attacker to supply a crafted HTML page that could bypass the browser sandbox and execute arbitrary code. The flaw is vulnerable to social engineering, as it requires a user to open or view the malicious content in Chrome. This abuse could compromise the confidentiality, integrity, and availability of the affected device.

Affected Systems

Versions of Google Chrome for Android older than 155.0.8059.39 are affected. The issue applies to any Android device running Chrome before this release, regardless of the device model or manufacturer.

Risk and Exploitability

The flaw has a CVSS score of 9.6, indicating a high severity risk. It is not listed in the CISA KEV catalog and, as EPSS is not available, the exploitation probability remains uncertain. However, the requirement for social engineering and user interaction still places it at moderate risk, making large‑scale deployment unlikely.

Generated by OpenCVE AI on October 7, 2026 at 02:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or newer on all Android devices
  • Disable or limit the Search functionality via Chrome policy or settings if possible
  • Maintain up‑to‑date anti‑phishing and safe‑browsing protections to reduce the chance of a user engaging with malicious content

Generated by OpenCVE AI on October 7, 2026 at 02:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 02:30:00 +0000

Type Values Removed Values Added
Title Chrome Search authorization flaw permitting arbitrary code execution

Tue, 06 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Title Chrome Search authorization flaw permitting arbitrary code execution

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:45:18.032Z

Reserved: 2026-10-06T16:33:10.799Z

Link: CVE-2026-106241

cve-icon Vulnrichment

Updated: 2026-10-06T20:45:15.303Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:51.030

Modified: 2026-10-06T21:17:08.120

Link: CVE-2026-106241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T02:15:10Z

Weaknesses