CVE-2026-106426 — Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox…
Description
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Changed
Scope
C
High
Confidentiality
I
High
Integrity
A
High
Availability
Affected
- Vendor
- Product
- chrome
Versions
- < 155.0.8059.39
Stated as the source expressed them.
References
Related threats
same CWE or vendorCVE-2026-84230 — IBM Guardium Data Protection 12.2.2 could allow a remote attacker to cause a denial of service due to a race condition resulting from concurrent un…
CVE-2026-84230 · 2h ago
CVE-2026-84271 — IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer.
CVE-2026-84271 · 4h ago
CVE-2026-42698 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Themeum Tutor LMS tutor allows Leverag…
CVE-2026-42698 · 10h ago
CVE-2026-94584 — A race condition and thread-safety vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1.
CVE-2026-94584 · 20h ago
CVE-2026-94583 — A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1.
CVE-2026-94583 · 21h ago
CVE-2026-107276 — MISP contains a race condition in the email-based one-time password (OTP) login flow.
CVE-2026-107276 · 1d ago