Threat reportVulnerabilityTL-2026-3151
Multiple Vulnerabilities in Google Chrome prior to 155.0.8059.39 (incl. CVE-2026-102322 SiteIsolation RCE and CVE-2026-106386 WebAudio, public PoC reported)
Multiple Vulnerabilities in Google Chrome prior to (TL-2026-3151), also tracked as GovCERT.HK A26-10-12, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-09. It has no confirmed attribution, affects Google Chrome, references 2 CVEs (CVE-2026-102322, CVE-2026-106386), maps to 2 MITRE ATT&CK techniques (T1203, T1204.001), and is covered by 9 detection rules and 8 indicators of compromise.
- CVSS
- 9.6/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 2MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-3151
- Threat ID
- TL-2026-3151
- Also known as
- GovCERT.HK A26-10-12, Chrome 155 Stable Security Update
- Severity
- CRITICAL
- CVSS
- 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education, telecoms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
How Multiple Vulnerabilities in Google Chrome prior to works
Google fixed roughly 247 security issues (four rated critical) in Chrome 155.0.8059.39/.40 on 2026-10-06/07. GovCERT.HK alert A26-10-12 rates the batch High Threat and reports public PoC code for CVE-2026-106386; no in-the-wild exploitation is stated in any reviewed source.
Google Chrome stable 155 (155.0.8059.39 for Linux and Android, 155.0.8059.39/.40 for Windows and Mac, 155.0.8059.37 for iOS per press coverage) was released on 2026-10-06/07. Press coverage (Deskmodder) counts 247 security fixes, four of them critical, and cites the release notes as stating no exploit was included. HKCERT bulletin of 2026-10-07 lists 327 CVE identifiers from CVE-2026-102322 through CVE-2026-106427 (gap at 106218/106219) and a Medium risk rating. GovCERT.HK alert A26-10-12 (2026-10-08) lists CVE-2026-102322, CVE-2026-106179 to -106217, -106220 to -106318 and -106320 to -106427, rates the batch High Threat, and states that successful exploitation could lead to remote code execution, denial of service, elevation of privilege, information disclosure, security restriction bypass, spoofing or tampering.
Two CVEs are individually documented in public CVE feeds. CVE-2026-102322 is an Incorrect Authorization flaw (CWE-863) in Chrome SiteIsolation that lets a remote attacker execute arbitrary code via a crafted HTML page; it is scored CVSS 3.1 9.6 Critical (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), Chromium issue 527023137. CVE-2026-106386 is the CVE that GovCERT.HK flags as RCE with public PoC. However, the NVD record describes it as an uninitialized resource flaw (CWE-908) in WebAudio that allows in-sandbox memory disclosure via a crafted HTML page, CVSS 3.1 6.5 Medium (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N), Chromium issue 553156221, status Undergoing Analysis as of 2026-10-07. This is a discrepancy between sources: the RCE characterization comes only from the GovCERT.HK alert, and the PoC itself was not located or analyzed.
The attack vector common to both documented CVEs is a victim visiting an attacker-controlled or compromised web page (drive-by). No threat actor, malware, C2 infrastructure or in-the-wild exploitation is stated in any reviewed source, so no network IOCs exist to correlate with BeaconBeagle. The remaining ~320 CVEs in the range were not individually verified; their details are not asserted here. Defenders should update to 155.0.8059.39 or later and relaunch the browser.
MITRE ATT&CK techniques used in TL-2026-3151
Execution
T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link
Affected products and versions in Multiple Vulnerabilities in Google Chrome prior to
- Google — Chrome
Vulnerable versions: Linux < 155.0.8059.39; Windows < 155.0.8059.39/.40; Mac < 155.0.8059.39/.40
Fixed in: 155.0.8059.39 (Linux); 155.0.8059.39/.40 (Windows, Mac)
Remediation for Multiple Vulnerabilities in Google Chrome prior to
Patches
- Google Chrome 155.0.8059.39 (Linux, Android)
- Google Chrome 155.0.8059.39/.40 (Windows, Mac)
Immediate actions
- Update Google Chrome to 155.0.8059.39 or later (155.0.8059.39/.40 on Windows and Mac) and relaunch the browser
- Verify version via About Google Chrome (chrome://settings/help) across the fleet
Workarounds
- No vendor workaround documented in reviewed sources; restrict browsing of untrusted sites on unpatched endpoints until updated
Longer-term hardening
- Enforce managed browser auto-update policies and a short patch SLA for Chromium-based browsers
- Track Chromium-based browsers (Edge, Brave, Opera, Electron apps) for downstream fixes of the same Chromium release
CVEs associated with Multiple Vulnerabilities in Google Chrome prior to
Weaknesses (CWE) in Multiple Vulnerabilities in Google Chrome prior to
Timeline of Multiple Vulnerabilities in Google Chrome prior to
- CVE-2026-102322 (SiteIsolation incorrect authorization, CVSS 9.6) disclosed with Chromium issue 527023137.
- Google publishes the Chrome stable desktop update announcement; CVE-2026-102322 is received and published in CVE feeds.
- NVD/CISA SSVC data for CVE-2026-106386 records exploitation status as PoC, not automatable, partial technical impact; no in-the-wild exploitation recorded.
- HKCERT publishes bulletin covering 327 CVEs (CVE-2026-102322 to CVE-2026-106427), Medium risk.
- NVD lists CVE-2026-106386 as WebAudio uninitialized resource (CVSS 6.5 Medium), Undergoing Analysis.
- Chrome 155 (155.0.8059.39/.40) distributed on Windows, Mac, Linux and Android; press reports 247 fixes, four critical, and no exploit noted in release notes.
- NVD completes initial analysis of CVE-2026-102322.
- GovCERT.HK issues High Threat alert A26-10-12 stating public PoC exists for CVE-2026-106386 (RCE).
Sources cited for Multiple Vulnerabilities in Google Chrome prior to
- High Threat Security Alert (A26-10-12): Multiple Vulnerabilities in Google Chrome
- HKCERT Security Bulletin: Google Chrome Multiple Vulnerabilities
- Chrome Releases: Stable Channel Update for Desktop (October 2026)
- NVD: CVE-2026-106386
- CVE-2026-102322 analysis (The Hacker Wire)
- Google Chrome 155 mit 247 Sicherheitskorrekturen verteilt (Deskmodder)
- Chromium issue 527023137 (CVE-2026-102322)
Detection coverage for TL-2026-3151
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3151 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.