Threat reportVulnerabilityTL-2026-3151

Multiple Vulnerabilities in Google Chrome prior to 155.0.8059.39 (incl. CVE-2026-102322 SiteIsolation RCE and CVE-2026-106386 WebAudio, public PoC reported)

criticalACTIVE

Multiple Vulnerabilities in Google Chrome prior to (TL-2026-3151), also tracked as GovCERT.HK A26-10-12, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-09. It has no confirmed attribution, affects Google Chrome, references 2 CVEs (CVE-2026-102322, CVE-2026-106386), maps to 2 MITRE ATT&CK techniques (T1203, T1204.001), and is covered by 9 detection rules and 8 indicators of compromise.

CVSS
9.6/10Critical
CVEs
2Referenced vulnerabilities
Techniques
2MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-3151

Threat ID
TL-2026-3151
Also known as
GovCERT.HK A26-10-12, Chrome 155 Stable Security Update
Severity
CRITICAL
CVSS
9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, education, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
8

How Multiple Vulnerabilities in Google Chrome prior to works

Google fixed roughly 247 security issues (four rated critical) in Chrome 155.0.8059.39/.40 on 2026-10-06/07. GovCERT.HK alert A26-10-12 rates the batch High Threat and reports public PoC code for CVE-2026-106386; no in-the-wild exploitation is stated in any reviewed source.

Google Chrome stable 155 (155.0.8059.39 for Linux and Android, 155.0.8059.39/.40 for Windows and Mac, 155.0.8059.37 for iOS per press coverage) was released on 2026-10-06/07. Press coverage (Deskmodder) counts 247 security fixes, four of them critical, and cites the release notes as stating no exploit was included. HKCERT bulletin of 2026-10-07 lists 327 CVE identifiers from CVE-2026-102322 through CVE-2026-106427 (gap at 106218/106219) and a Medium risk rating. GovCERT.HK alert A26-10-12 (2026-10-08) lists CVE-2026-102322, CVE-2026-106179 to -106217, -106220 to -106318 and -106320 to -106427, rates the batch High Threat, and states that successful exploitation could lead to remote code execution, denial of service, elevation of privilege, information disclosure, security restriction bypass, spoofing or tampering.

Two CVEs are individually documented in public CVE feeds. CVE-2026-102322 is an Incorrect Authorization flaw (CWE-863) in Chrome SiteIsolation that lets a remote attacker execute arbitrary code via a crafted HTML page; it is scored CVSS 3.1 9.6 Critical (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), Chromium issue 527023137. CVE-2026-106386 is the CVE that GovCERT.HK flags as RCE with public PoC. However, the NVD record describes it as an uninitialized resource flaw (CWE-908) in WebAudio that allows in-sandbox memory disclosure via a crafted HTML page, CVSS 3.1 6.5 Medium (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N), Chromium issue 553156221, status Undergoing Analysis as of 2026-10-07. This is a discrepancy between sources: the RCE characterization comes only from the GovCERT.HK alert, and the PoC itself was not located or analyzed.

The attack vector common to both documented CVEs is a victim visiting an attacker-controlled or compromised web page (drive-by). No threat actor, malware, C2 infrastructure or in-the-wild exploitation is stated in any reviewed source, so no network IOCs exist to correlate with BeaconBeagle. The remaining ~320 CVEs in the range were not individually verified; their details are not asserted here. Defenders should update to 155.0.8059.39 or later and relaunch the browser.

MITRE ATT&CK techniques used in TL-2026-3151

Execution

T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link

Affected products and versions in Multiple Vulnerabilities in Google Chrome prior to

  • Google — Chrome
    Vulnerable versions: Linux < 155.0.8059.39; Windows < 155.0.8059.39/.40; Mac < 155.0.8059.39/.40
    Fixed in: 155.0.8059.39 (Linux); 155.0.8059.39/.40 (Windows, Mac)

Remediation for Multiple Vulnerabilities in Google Chrome prior to

Patches

  • Google Chrome 155.0.8059.39 (Linux, Android)
  • Google Chrome 155.0.8059.39/.40 (Windows, Mac)

Immediate actions

  • Update Google Chrome to 155.0.8059.39 or later (155.0.8059.39/.40 on Windows and Mac) and relaunch the browser
  • Verify version via About Google Chrome (chrome://settings/help) across the fleet

Workarounds

  • No vendor workaround documented in reviewed sources; restrict browsing of untrusted sites on unpatched endpoints until updated

Longer-term hardening

  • Enforce managed browser auto-update policies and a short patch SLA for Chromium-based browsers
  • Track Chromium-based browsers (Edge, Brave, Opera, Electron apps) for downstream fixes of the same Chromium release

CVEs associated with Multiple Vulnerabilities in Google Chrome prior to

CVE-2026-102322, CVE-2026-106386

Weaknesses (CWE) in Multiple Vulnerabilities in Google Chrome prior to

CWE-863, CWE-908

Timeline of Multiple Vulnerabilities in Google Chrome prior to

  • CVE-2026-102322 (SiteIsolation incorrect authorization, CVSS 9.6) disclosed with Chromium issue 527023137.
  • Google publishes the Chrome stable desktop update announcement; CVE-2026-102322 is received and published in CVE feeds.
  • NVD/CISA SSVC data for CVE-2026-106386 records exploitation status as PoC, not automatable, partial technical impact; no in-the-wild exploitation recorded.
  • HKCERT publishes bulletin covering 327 CVEs (CVE-2026-102322 to CVE-2026-106427), Medium risk.
  • NVD lists CVE-2026-106386 as WebAudio uninitialized resource (CVSS 6.5 Medium), Undergoing Analysis.
  • Chrome 155 (155.0.8059.39/.40) distributed on Windows, Mac, Linux and Android; press reports 247 fixes, four critical, and no exploit noted in release notes.
  • NVD completes initial analysis of CVE-2026-102322.
  • GovCERT.HK issues High Threat alert A26-10-12 stating public PoC exists for CVE-2026-106386 (RCE).

Sources cited for Multiple Vulnerabilities in Google Chrome prior to

Detection coverage for TL-2026-3151

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3151 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats