Description
Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a buffer overflow that occurs within the font rendering component of Google Chrome. A remote attacker, after compromising the renderer process, can trigger the overflow by delivering a specially crafted HTML page, potentially allowing execution of arbitrary code outside the sandbox. The primary impact is remote code execution with the ability to escape sandbox protections. The likely attack vector is inferred to be through a malicious web page or data that the user opens, which would be parsed by the compromised renderer.

Affected Systems

Google Chrome versions earlier than 155.0.8059.39 are affected. These include all builds of the stable channel prior to the mentioned version.

Risk and Exploitability

The CVSS score is not explicitly provided in the data, and the EPSS score is unavailable, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires prior compromise of the renderer process, the attack conditions are relatively high. However, once the renderer is compromised, the attacker can achieve remote code execution beyond Chrome’s sandbox. The vendor’s public release notes indicate that the issue is fixed in 155.0.8059.39; therefore, updating mitigates the risk.

Generated by OpenCVE AI on October 6, 2026 at 21:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or newer, which includes a patched font renderer.
  • Install updates promptly and enable automatic update features to keep the browser current.
  • Avoid opening or executing untrusted or downloaded HTML files that could contain malicious font data until a patch is applied.

Generated by OpenCVE AI on October 6, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in Chrome Font Rendering Enables Code Execution

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-122
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:05:43.038Z

Reserved: 2026-10-06T16:34:27.114Z

Link: CVE-2026-106292

cve-icon Vulnrichment

Updated: 2026-10-06T20:00:11.616Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:57.110

Modified: 2026-10-06T21:17:10.350

Link: CVE-2026-106292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:00:08Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow