PatchSiren cyber security CVE debrief
CVE-2026-106405 Google CVE debrief
A race condition vulnerability in Google Chrome's CustomTabs on Android prior to version 155.0.8059.39 allows a local attacker to bypass web origin policy via a co-installed app. This issue, reported by the Chromium security team with a medium severity rating, highlights the importance of keeping Chrome up-to-date on Android devices. The vulnerability was reported through the Chromium security program and patched in version 155.0.8059.39. Chrome users on Android should verify their version and update if necessary.
- Vendor
- Product
- Chrome
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for managing Google Chrome deployments on Android devices should assess exposure and prioritize updates to mitigate this vulnerability. Security teams and IT administrators managing Chrome on Android should review the CVE record and source information to understand the affected scope and necessary actions. Operators of Chrome on Android devices should verify their version and update if necessary to prevent exploitation.
Why it matters
CVE-2026-106405 is a medium-severity vulnerability in Google Chrome's CustomTabs on Android prior to version 155.0.8059.39. Defenders should prioritize updates to mitigate the risk of local attackers bypassing web origin policy via co-installed apps.
- Local attackers may bypass web origin policy on affected Chrome versions
- Successful exploitation requires a co-installed app on the same device
- Defenders should verify Chrome versions on Android devices
- Updating Chrome to version 155.0.8059.39 or later mitigates this vulnerability
Technical summary
A race condition vulnerability in Google Chrome's CustomTabs on Android prior to version 155.0.8059.39 allows a local attacker to bypass web origin policy via a co-installed app. This issue was reported through the Chromium security program and patched in version 155.0.8059.39. The vulnerability has a medium severity rating according to the Chromium security team. Chrome users on Android should verify their version and update if necessary to mitigate this vulnerability. The vulnerability affects Chrome on Android devices and requires a co-installed app to exploit.
Defensive priority
Defenders should prioritize updating Chrome to version 155.0.8059.39 or later on Android devices to mitigate this vulnerability.
Recommended defensive actions
- Update Google Chrome to version 155.0.8059.39 or later on Android devices
- Verify that Chrome is up-to-date on all Android devices
- Monitor Chrome releases for future updates
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to additional information. The Chromium security team reported this issue with a medium severity rating. Chrome release notes and the Chromium issue tracker provide additional context. The CVE Program record and NIST NVD detail page offer further information on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106405 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106405
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106405 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106405
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-106405
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106405.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/517150523
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.