Description
Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Patch Now
AI Analysis

Impact

The vulnerability arises from incomplete cleanup in the Dawn rendering engine in Google Chrome versions prior to 155.0.8059.39. A crafted HTML page can trigger code execution outside the sandbox, allowing an attacker to run arbitrary code on the affected system. The weakness maps to CWE-459 (Improper Output Neutralization for Security-related Data).

Affected Systems

Affected products are Google Chrome browsers used on desktop platforms. Users with any Chrome build older than 155.0.8059.39 are potentially vulnerable. The most recent secure release is 155.0.8059.39 and later.

Risk and Exploitability

The CVE is rated as medium severity in Chromium's own scoring, and its EPSS score is not available, meaning the recent exploitation probability is unknown. It is also not listed in the CISA KEV catalog. Externally, the attack requires a user to open a maliciously crafted HTML page, so it is a remote attack that could be delivered via phishing or compromised websites. Because the flaw bypasses the sandbox, successfully exploited code could perform any action with the privileges of the browser process.

Generated by OpenCVE AI on October 6, 2026 at 22:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 155.0.8059.39 or newer.
  • Enable automatic updates and verify that the browser receives the latest patch.
  • Restrict execution of untrusted local files and disable JavaScript for downloaded HTML files until a patch is applied.

Generated by OpenCVE AI on October 6, 2026 at 22:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Incomplete Dawn Cleanup in Chrome

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-459
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:37:30.208Z

Reserved: 2026-10-06T16:36:57.416Z

Link: CVE-2026-106375

cve-icon Vulnrichment

Updated: 2026-10-06T20:37:27.159Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:06.630

Modified: 2026-10-06T21:17:14.140

Link: CVE-2026-106375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:15:06Z

Weaknesses