CVE-2026-103626

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-02: 110-02
Referenced assets1 URL
Full discourse1 post
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CHROME STABLE UPDATE — 11 SECURITY FIXES INCLUDING CRITICAL WEBGL CVE Google issued a new Stable Channel Update for Desktop on October 1, 2026, advancing Chrome 154 with 11 security fixes. The security details list is now live (earlier monitor runs saw only “updated shortly”). • Versions: 154.0.8037.97/.98 (Windows/Mac); 154.0.8037.97 (Linux) • Rollout: gradual Stable channel over coming days/weeks • Critical: CVE-2026-103628 — Out of bounds write in WebGL • High: CVE-2026-103626 FileSystem, CVE-2026-103621 Compositing, CVE-2026-103630 FedCM, CVE-2026-103625 V8, CVE-2026-103624 Contextual Tasks, CVE-2026-103629 Skia, CVE-2026-103622 SVG, CVE-2026-103623 MediaStream, CVE-2026-103631 WebRTC • Medium: CVE-2026-103627 SVG • Distinct from the September 29 Chrome Stable update (154.0.8037.92/.93, Critical CVE-2026-102331) already covered on @DailyDarkWeb ⚠️ Analyst Note: This is the official Google Chrome Releases Stable Channel Update for Desktop dated October 1, 2026 — a new mid-cycle security build with the CVE list now published, not a rehash of the Sep 29 Stable update. Google often keeps bug details and links restricted until a majority of users are updated. These CVEs are not in KEV; the advisory does not claim exploitation in the wild. Update Chrome promptly via Help → About Google Chrome (or your managed update channel). Official: https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html #DDW #DarkWeb #Chrome #CVE #CVE2026103628

    200415.3K
    206.1K followersView on X

Explore more