Arbitrary Code Execution Vulnerability in Google Chrome for Windows
CVE-2026-103626

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-103626?

An improper authorization vulnerability was discovered in the FileSystem component of Google Chrome on Windows, which affects versions prior to 154.0.8037.97. This flaw allows remote attackers to exploit social engineering techniques to execute arbitrary code outside the secure sandbox environment by manipulating crafted HTML pages. Users are urged to update their browsers promptly to mitigate the risk associated with this security issue.

Affected Version(s)

Chrome 154.0.8037.97

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.