External risk intelligence

Chrome UI Vulnerability Allows Potential Arbitrary Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-106372

This vulnerability is located within a web browser's UI. Successful exploitation requires a user to navigate to a specifically crafted HTML page. It is a client-side interaction rather than an internet-facing service, appliance, or gateway that is public-facing by design.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability in Google Chrome's user interface could allow attackers to execute unauthorized code on user devices through specially crafted web pages. While the immediate risk is mitigated by requiring user interaction with a malicious page, the potential for remote code execution warrants attention to confirm if our specific Chrome usage is exposed.

  • Flaw allows unauthorized code execution via web pages.
  • Significant, but needs user interaction to exploit.
  • Confirm relevance and potential exposure to this flaw.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious webpage that exploits a flaw in the Chrome browser's user interface. This could allow the attacker to break out of the browser's security sandbox and potentially run their own code on the user's computer.

  • Attacker needs to lure user to a malicious page.
  • Vulnerability is in the browser's user interface.
  • Risk of arbitrary code execution outside sandbox.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker could potentially execute arbitrary code outside the sandbox by luring a user to a specially crafted HTML page. This could affect the user's ability to safely browse the internet.

  • User's system and data.
  • Visiting a malicious website.
  • Arbitrary code execution and data compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Google Chrome's UI requires a user to visit a malicious HTML page, indicating a client-side attack vector. The primary responsibility for addressing this will likely fall to teams managing end-user computing environments, such as IT support or device management, in coordination with security teams to confirm exposure and plan remediation. The first practical step involves identifying Chrome instances, assessing their exposure, and confirming ownership before proceeding with updates.

  • Identify Chrome instances and owners.
  • Verify user exposure and criticality.
  • Plan targeted updates or mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome and why does it have a UI component?

Google Chrome is a widely used web browser that renders web content and manages user interactions. The User Interface (UI) is the portion of the software that manages address bars, menus, and tab controls. Because these elements bridge the gap between the internet and your local machine, they must enforce strict security boundaries to prevent web content from accessing your underlying operating system.

What does CWE-863 mean in the context of CVE-2026-106372?

CWE-863 stands for Incorrect Authorization. In this CVE, it means the browser's UI component fails to properly verify or enforce permissions before performing a sensitive action. Instead of rejecting unauthorized requests, the UI mistakenly allows a remote webpage to perform operations it should not have the authority to execute, ultimately leading to code execution outside the security sandbox.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by luring a user to visit a specifically crafted HTML page. The vulnerability is not triggered by simply having Chrome installed or having it running in the background. It specifically requires the user to actively navigate to a malicious site, meaning standard, legitimate web browsing does not trigger the bug.

Is my device at risk if Chrome is internal-only?

According to Halo Surface Signal, this vulnerability is considered 'Very unlikely' to pose a high risk because it is a client-side issue rather than a public-facing server. Because the attack depends on a user visiting a malicious site, the threat level is generally the same regardless of whether your device is on an internal network or exposed to the internet.

What is the first step to address CVE-2026-106372?

The most effective first step is to identify all systems in your environment currently running versions of Chrome older than 155.0.8059.39. Once you have an inventory of these devices, prioritize updating them to the latest stable release. Coordination with IT and device management teams is essential to ensure these updates are deployed to all users effectively.

References