PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106363 Google CVE debrief

A missing authorization vulnerability in Google Chrome's FullScreen feature prior to version 155.0.8059.39 could allow a remote attacker to bypass system access restrictions via a crafted HTML page, provided they had compromised the renderer process and used social engineering tactics. This vulnerability requires a compromised renderer process and social engineering to exploit, posing a risk that needs to be addressed. Defenders responsible for Chrome deployments should assess exposure, especially in environments where users have access to the FullScreen feature, and prioritize patching or mitigation.

Vendor
Google
Product
Chrome
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-08
Advisory published
2026-10-06
Advisory updated
2026-10-08

Who should care

Defenders responsible for managing Google Chrome deployments, particularly in environments where users have access to the FullScreen feature, should assess exposure and prioritize patching or mitigation to prevent potential unauthorized actions.

Why it matters

Defenders should care about CVE-2026-106363 because it involves a missing authorization vulnerability in Google Chrome's FullScreen feature, which could allow remote attackers to bypass system access restrictions. This vulnerability requires a compromised renderer process and social engineering tactics to exploit. Defenders responsible for Chrome deployments should assess exposure, especially in environments where users have access to the FullScreen feature, and prioritize patching or mitigation to prevent potential unauthorized actions. The impact of this vulnerability is currently limited by the requirement for a compromised renderer process and social engineering, but it still poses a risk that needs to be addressed.

  • Potential unauthorized system access via crafted HTML pages
  • Increased risk of social engineering attacks
  • Possible bypass of access restrictions in Chrome's FullScreen feature
  • Need for verification of Chrome version and exposure

Technical summary

The vulnerability exists in Google Chrome's FullScreen feature prior to version 155.0.8059.39. A remote attacker who has compromised the renderer process and uses social engineering tactics could bypass system access restrictions via a crafted HTML page. This vulnerability requires a compromised renderer process and social engineering to exploit. Defenders should prioritize patching or mitigating this vulnerability, especially for systems and users with access to Chrome's FullScreen feature, to prevent potential unauthorized actions.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability, especially for systems and users with access to Chrome's FullScreen feature, to prevent potential unauthorized actions.

Recommended defensive actions

  • Patch or upgrade Google Chrome to version 155.0.8059.39 or later
  • Implement additional security measures to protect against social engineering attacks
  • Monitor system access and user activity for potential unauthorized actions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its existence in Chrome versions prior to 155.0.8059.39 and the required conditions for exploitation. However, specific details about the vulnerability's impact and exploitation are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106363 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106363

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106363 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106363

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-106363

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106363.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://issues.chromium.org/issues/501896592

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.