Description
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw is a race condition in the font handling subsystem of Google Chrome versions earlier than 155.0.8059.39. It permits a crafted HTML page to trigger a timing discrepancy during font processing, which can break out of the browser sandbox and allow execution of arbitrary code on the host system. The weakness is catalogued as CWE-362, reflecting the concurrent manipulation of shared data. The impact is therefore denial of system integrity at a system-wide level, as the attacker could gain full privileges depending on the operating system's sandbox boundaries.

Affected Systems

The affected product is Google Chrome, across all desktop platforms that ship with any version prior to 155.0.8059.39. The exact versions are unlisted in the vendor data, but the reference release notes indicate the fix is present in the 155.0.8059.40 update. Users running older Windows, macOS, or Linux builds of Chrome are vulnerable.

Risk and Exploitability

The CVSS score of 8.3 classifies this as high severity. The EPSS score is not available, but the absence of a KEV listing does not mitigate the risk; the vulnerability remains medium to high likelihood of exploitation in the wild, especially for malicious websites or phishing pages. The likely attack vector is a remote adversary serving a malicious HTML payload to a victim’s browser, exploiting the font race condition to escape the sandbox.

Generated by OpenCVE AI on October 7, 2026 at 03:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.40 or newer, following the stable channel release notes on the Chrome blog
  • Deploy a Chrome enterprise policy to disable remote font loading (set DisableRemoteFonts to true) to reduce the attack surface
  • Apply OS-level security updates that may enhance sandbox isolation or graphics subsystem security while the browser update is pending

Generated by OpenCVE AI on October 7, 2026 at 03:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 07 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:30:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome Fonts Enables Sandbox Escape via Crafted HTML

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-362
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:56:11.179Z

Reserved: 2026-10-06T16:39:05.103Z

Link: CVE-2026-106426

cve-icon Vulnrichment

Updated: 2026-10-06T20:52:24.856Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:18:12.483

Modified: 2026-10-07T13:38:48.257

Link: CVE-2026-106426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:00:08Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')