# Multiple Vulnerabilities in Google Chrome prior to 155.0.8059.39 (incl. CVE-2026-102322 SiteIsolation RCE and CVE-2026-106386 WebAudio, public PoC reported)

> Google fixed roughly 247 security issues (four rated critical) in Chrome 155.0.8059.39/.40 on 2026-10-06/07. GovCERT.HK alert A26-10-12 rates the batch High Threat and reports public PoC code for CVE-2026-106386; no in-the-wild exploitation is stated in any reviewed source.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3151
- **ID:** TL-2026-3151
- **Severity:** CRITICAL (CVSS 9.6)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-102322, CVE-2026-106386

## Description

Google Chrome stable 155 (155.0.8059.39 for Linux and Android, 155.0.8059.39/.40 for Windows and Mac, 155.0.8059.37 for iOS per press coverage) was released on 2026-10-06/07. Press coverage (Deskmodder) counts 247 security fixes, four of them critical, and cites the release notes as stating no exploit was included. HKCERT bulletin of 2026-10-07 lists 327 CVE identifiers from CVE-2026-102322 through CVE-2026-106427 (gap at 106218/106219) and a Medium risk rating. GovCERT.HK alert A26-10-12 (2026-10-08) lists CVE-2026-102322, CVE-2026-106179 to -106217, -106220 to -106318 and -106320 to -106427, rates the batch High Threat, and states that successful exploitation could lead to remote code execution, denial of service, elevation of privilege, information disclosure, security restriction bypass, spoofing or tampering.

Two CVEs are individually documented in public CVE feeds. CVE-2026-102322 is an Incorrect Authorization flaw (CWE-863) in Chrome SiteIsolation that lets a remote attacker execute arbitrary code via a crafted HTML page; it is scored CVSS 3.1 9.6 Critical (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), Chromium issue 527023137. CVE-2026-106386 is the CVE that GovCERT.HK flags as RCE with public PoC. However, the NVD record describes it as an uninitialized resource flaw (CWE-908) in WebAudio that allows in-sandbox memory disclosure via a crafted HTML page, CVSS 3.1 6.5 Medium (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N), Chromium issue 553156221, status Undergoing Analysis as of 2026-10-07. This is a discrepancy between sources: the RCE characterization comes only from the GovCERT.HK alert, and the PoC itself was not located or analyzed.

The attack vector common to both documented CVEs is a victim visiting an attacker-controlled or compromised web page (drive-by). No threat actor, malware, C2 infrastructure or in-the-wild exploitation is stated in any reviewed source, so no network IOCs exist to correlate with BeaconBeagle. The remaining ~320 CVEs in the range were not individually verified; their details are not asserted here. Defenders should update to 155.0.8059.39 or later and relaunch the browser.

## MITRE ATT&CK

- T1203 Exploitation for Client Execution
- T1204.001 User Execution: Malicious Link

## Sources

- [High Threat Security Alert (A26-10-12): Multiple Vulnerabilities in Google Chrome](https://www.govcert.gov.hk/en/alerts_detail.php?id=2101)
- [HKCERT Security Bulletin: Google Chrome Multiple Vulnerabilities](https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20261007)
- [Chrome Releases: Stable Channel Update for Desktop (October 2026)](https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html)
- [NVD: CVE-2026-106386](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-106386)
- [CVE-2026-102322 analysis (The Hacker Wire)](https://www.thehackerwire.com/vulnerability/CVE-2026-102322/)
- [Google Chrome 155 mit 247 Sicherheitskorrekturen verteilt (Deskmodder)](https://www.deskmodder.de/blog/?p=218051)
- [Chromium issue 527023137 (CVE-2026-102322)](https://issues.chromium.org/issues/527023137)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3151
