Security NEXT•October 7, 2026•🇯🇵Translated from Japanese

Google Releases Chrome 155 Fixing 247 Vulnerabilities Including Four Critical Use-After-Free Flaws

Google has released Chrome 155 on October 6, 2026, addressing a total of 247 security issues across Windows, macOS, and Linux platforms. The update includes four critical vulnerabilities, all classified as use-after-free flaws that affect Chromecast, Browser, Navigation, and Track components.

Fifty-three high-severity issues were also resolved, covering problems in SiteIsolation, Core, Omnibox, FileSystem, ANGLE, WebGL, and multiple other modules. The critical CVEs fixed are CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347.

Additional fixes address use-after-free conditions, race conditions, type confusion, and integer overflows in V8, WebRTC, PDF, Media, Parser, Storage, and WebAudio. The new versions are Chrome 155.0.8059.40 for Windows and macOS and 155.0.8059.39 for Linux and macOS.

Related articles

Security NEXT•Vulnerabilities & Exploits

WordPress 7.1.3 Security Release Fixes Seven Vulnerabilities Including Stored XSS and SQL Injection

The WordPress development team has released version 7.1.3 as a maintenance and security update addressing multiple vulnerabilities. The release includes seven security fixes and four additional bug corrections. Among the security issues resolved is a stored cross-site scripting flaw that allowed pending comments to execute scripts in the administrative interface. Other fixes cover a denial-of-service condition in URL handling, an SQL injection vulnerability in the WXR export feature, and unauthorized disclosure of comments attached to private or unpublished posts. Additional patches address an XSS issue in the Imgur embed functionality, improper sticky post permissions for users with the Author role, and a parameter manipulation problem affecting hook action names.

Hispasec•Vulnerabilities & Exploits

LibreOffice and Apache OpenOffice Flaws Enable Remote Code Execution via Malicious Spreadsheets Without Macro Warnings

Two vulnerabilities, CVE-2026-63277 in LibreOffice Calc and CVE-2026-59265 in Apache OpenOffice, allow attackers to execute arbitrary code simply by tricking users into opening specially crafted spreadsheet files. The flaws exploit Java integration and class path handling, bypassing traditional macro security prompts entirely. LibreOffice has already released fixes in versions 26.2.5 and 26.8.0 that restrict class path entries to local file URLs only. Apache OpenOffice 4.1.16 and earlier remain vulnerable, with the stable patch expected in 4.1.17; interim mitigation requires disabling Java integration. The issues highlight risks in office suites that process untrusted documents containing external data connections or JDBC references. Organizations are advised to enforce least-privilege execution and avoid opening files from unknown sources until patches are applied.

BoletimSec•Vulnerabilities & Exploits

Web Application Vulnerabilities Surge as AI-Driven Development Outpaces Security Testing

The number of vulnerabilities in web applications continues to grow each quarter, driven in part by the rapid adoption of artificial intelligence in software development pipelines. While integrating AI tools boosts productivity and shortens release cycles, many organizations fail to match this speed with equivalent security testing and validation processes. As a result, increasing amounts of code reach production environments without ever being assessed from an attacker’s perspective. Cybercriminals have quickly recognized this gap, exploiting repeated flaw patterns in applications that skip security reviews. The article emphasizes that pentesting must become a recurring part of the development cycle, conducted weekly or monthly to match the pace of updates. Continuous security testing allows teams to identify and remediate issues before they can be weaponized. Developing rapidly with AI is not inherently risky, but releasing unvalidated code transforms speed into exposure.

BoletimSec•Vulnerabilities & Exploits

Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access

Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.