That 'critical, 9.6' Chrome bug? Google itself calls it Low severity

A newly published Chrome flaw comes with a scary NVD score and a very different verdict from the people who actually wrote the fix.

Futuristic circuit board with glowing blue arcs and spheres
Photo · Brecht Corbeel / Unsplash

The headline number doesn’t match the small print

CVE-2026-106237 has just landed in the National Vulnerability Database with a CVSS score of 9.6 — the kind of number that normally means “drop what you’re doing.” The bug itself is described as an information leak in Chrome’s Permissions handling, which a remote attacker could exploit with a crafted webpage to bypass site isolation, the sandboxing system that’s supposed to stop one tab’s web content from peeking at another’s.

That sounds serious. But buried in the same NVD entry is a detail that undercuts the drama: Chromium’s own security team classifies this bug as “Low” severity. That’s a big gap between the automated CVSS maths and the judgement of the engineers who actually triaged it, and it’s worth understanding why before anyone panics.

What the bug actually does

Site isolation is one of Chrome’s core defences — each site effectively gets its own sandboxed process, so a malicious page can’t easily read data belonging to, say, your banking site open in another tab. CVE-2026-106237 is said to allow that boundary to leak information via the Permissions system, triggered by specially crafted HTML.

Google hasn’t published the technical write-up yet. The associated bug tracker entry on issues.chromium.org remains restricted, which is standard practice while Google waits for the fix to roll out to most users before revealing exploit details that could help attackers target stragglers.

Crucially, nothing in Google’s stable channel release notes or the NVD listing indicates this bug has been exploited in the wild. It was found and fixed proactively, as part of a routine update bundling 24 security fixes, several of them use-after-free and race-condition issues rated Critical or High by Chromium — categories that tend to be far more dangerous in practice than an info leak capped at “Low.”

So who is actually at risk

Short answer: nobody who keeps Chrome updated. The fix shipped in Chrome 155.0.8059.39 (155.0.8059.40 on Windows and Mac) on 6 October 2026, rolling out across Windows, Mac and Linux over the following days and weeks. If you’re on a current version, you’re already covered.

The CVSS 9.6 score is a generic estimate based on the type of flaw (remote, no privileges needed, potential confidentiality impact) rather than a measured real-world exploit chain. Chromium’s “Low” tag reflects its internal severity model, which weighs things like how hard the bug is to actually trigger and what an attacker would realistically gain. The two systems are answering different questions, and conflating them is how modest bugs end up looking like emergencies in headlines.

What to do about it

There’s one genuinely useful action here, and it’s the same one that applies to basically every Chrome update: make sure Chrome is current. Check via the three-dot menu → Help → About Google Chrome, which will auto-update if you’re behind. The same build also closes four Critical-rated use-after-free bugs, which are a more plausible route to real harm than this particular leak.

The takeaway

CVE-2026-106237 is real, patched, and not known to be under active attack. The eye-catching 9.6 score says more about how CVSS calculates risk than about any looming threat to ordinary users — Chromium’s own “Low” rating is the more grounded read. Update your browser as usual, and don’t let the number do your thinking for you.

Sources