PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106405 Google CVE debrief

A race condition vulnerability in Google Chrome's CustomTabs on Android prior to version 155.0.8059.39 allows a local attacker to bypass web origin policy via a co-installed app. This issue, reported by the Chromium security team with a medium severity rating, highlights the importance of keeping Chrome up-to-date on Android devices. The vulnerability was reported through the Chromium security program and patched in version 155.0.8059.39. Chrome users on Android should verify their version and update if necessary.

Vendor
Google
Product
Chrome
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-08
Advisory published
2026-10-06
Advisory updated
2026-10-08

Who should care

Defenders responsible for managing Google Chrome deployments on Android devices should assess exposure and prioritize updates to mitigate this vulnerability. Security teams and IT administrators managing Chrome on Android should review the CVE record and source information to understand the affected scope and necessary actions. Operators of Chrome on Android devices should verify their version and update if necessary to prevent exploitation.

Why it matters

CVE-2026-106405 is a medium-severity vulnerability in Google Chrome's CustomTabs on Android prior to version 155.0.8059.39. Defenders should prioritize updates to mitigate the risk of local attackers bypassing web origin policy via co-installed apps.

  • Local attackers may bypass web origin policy on affected Chrome versions
  • Successful exploitation requires a co-installed app on the same device
  • Defenders should verify Chrome versions on Android devices
  • Updating Chrome to version 155.0.8059.39 or later mitigates this vulnerability

Technical summary

A race condition vulnerability in Google Chrome's CustomTabs on Android prior to version 155.0.8059.39 allows a local attacker to bypass web origin policy via a co-installed app. This issue was reported through the Chromium security program and patched in version 155.0.8059.39. The vulnerability has a medium severity rating according to the Chromium security team. Chrome users on Android should verify their version and update if necessary to mitigate this vulnerability. The vulnerability affects Chrome on Android devices and requires a co-installed app to exploit.

Defensive priority

Defenders should prioritize updating Chrome to version 155.0.8059.39 or later on Android devices to mitigate this vulnerability.

Recommended defensive actions

  • Update Google Chrome to version 155.0.8059.39 or later on Android devices
  • Verify that Chrome is up-to-date on all Android devices
  • Monitor Chrome releases for future updates
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to additional information. The Chromium security team reported this issue with a medium severity rating. Chrome release notes and the Chromium issue tracker provide additional context. The CVE Program record and NIST NVD detail page offer further information on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106405 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106405

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106405 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106405

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-106405

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106405.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://issues.chromium.org/issues/517150523

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.