CVE-2026-106370: Uninitialized resource in Google Chrome
Description
CVE-2026-106370 is a medium severity vulnerability in Google Chrome on Android where an uninitialized GPU resource allowed a remote attacker with control over the renderer process to read memory outside the sandbox via a crafted HTML page. This affects versions prior to 155.0.8059.39. A vendor advisory is available but does not explicitly state patch status in the provided data.
Affected software
Chrome
pkg:github/chromium/chromiumRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves an uninitialized resource in the GPU component of Google Chrome on Android devices before version 155.0.8059.39. An attacker who has already compromised the renderer process can exploit this flaw by delivering a crafted HTML page that enables reading memory outside the sandbox, potentially exposing sensitive information. The Chromium security team has rated this issue as medium severity. The vendor advisory URL is provided but does not explicitly confirm patch availability in the input data.
Potential Impact
A remote attacker with control over the renderer process can read memory outside the sandbox, which may lead to information disclosure. The vulnerability requires prior compromise of the renderer process, limiting the attack surface. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html for current remediation guidance. Until confirmed patched, users should update Chrome on Android to version 155.0.8059.39 or later once available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-10-06T16:36:45.111Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","vendor":"Google"}]
Threat ID: 6ac546582cdf04f656d4a067
Added to database: 10/06/2026, 19:04:56 UTC
Last enriched: 10/06/2026, 20:49:03 UTC
Last updated: 10/06/2026, 23:08:19 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.