Threat reportVulnerabilityTL-2026-3251

Chrome 155 Update Patches 247 Vulnerabilities Including 4 Critical Use-After-Free Flaws (CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347)

criticalPATCHED

Chrome 155 Update Patches 247 Vulnerabilities Including 4 (TL-2026-3251), also tracked as Chrome 155 security update, is a critical-severity software vulnerability, first published 2026-10-10. It has no confirmed attribution, affects Google Chrome (Windows, macOS, Linux), references 4 CVEs (CVE-2026-106382, CVE-2026-106197, CVE-2026-106358), maps to 2 MITRE ATT&CK techniques (T1203, T1204.001), and is covered by 9 detection rules and 7 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
4Referenced vulnerabilities
Techniques
2MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
7Indicators of compromise

Key facts for TL-2026-3251

Threat ID
TL-2026-3251
Also known as
Chrome 155 security update, Chrome 155.0.8059.39
Severity
CRITICAL
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
all sectors, enterprise, government administration, consumer
Target regions
Global
Detection rules
9
Indicators of compromise
7

How Chrome 155 Update Patches 247 Vulnerabilities Including 4 works

Google released Chrome 155 (155.0.8059.39/.40 for Windows/macOS, 155.0.8059.39 for Linux) fixing 247 security issues: 4 Critical, 53 High, 122 Medium and 68 Low. The four Critical flaws are use-after-free bugs in Chromecast, Browser, Navigation and Track; Google does not report exploitation in the wild.

On 2026-10-06/07 Google promoted Chrome 155 to the Stable channel with 247 security fixes, far above recent cadence (the 2026-10-01 desktop update 154.0.8037.97 contained 11 fixes). Fixed builds are 155.0.8059.39/.40 on Windows and macOS and 155.0.8059.39 on Linux, rolling out over days to weeks, with corresponding mobile releases.

Four bugs are rated Critical by the Chromium security team, all use-after-free (CWE-416): CVE-2026-106382 (Chromecast), CVE-2026-106197 (Browser), CVE-2026-106358 (Navigation) and CVE-2026-106347 (Track). Per the Debian security tracker, CVE-2026-106382, CVE-2026-106197 and CVE-2026-106358 allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page (i.e. a sandbox escape), while CVE-2026-106347 allows code execution inside the sandbox via a crafted HTML page. Chrome versions prior to 155.0.8059.39 are affected.

Per SecurityWeek, Google discovered the first Critical bug internally; researcher Xinyang Ge reported three Critical flaws and used AI to identify two additional defects. External researchers reported 62 of the fixes, with roughly $33,000 in bounties disclosed and nearly 50 reports lacking published reward amounts. The most common categories across the batch were incorrect authorization (41), use-after-free (34), missing authorization (34), UI misrepresentation (20) and information leak (17).

Google makes no mention of in-the-wild exploitation, no public PoC is cited in the sources, and no CVSS scores or detailed attack vectors were published at the time of research. This is a patch-prioritization item for a widely deployed browser rather than an active-exploitation campaign. As of the Debian tracker snapshot, distro Chromium packages (150.0.7871.100 and 154.0.8037.92 in bookworm, trixie, forky, sid) were still listed as vulnerable with no fixed version.

MITRE ATT&CK techniques used in TL-2026-3251

Execution

T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link

Affected products and versions in Chrome 155 Update Patches 247 Vulnerabilities Including 4

  • Google — Chrome (Windows, macOS, Linux)
    Vulnerable versions: < 155.0.8059.39
    Fixed in: 155.0.8059.39; 155.0.8059.40 (Windows/macOS)
  • Debian — Chromium
    Vulnerable versions: 150.0.7871.100; 154.0.8037.92

Remediation for Chrome 155 Update Patches 247 Vulnerabilities Including 4

Patches

  • Google Chrome 155.0.8059.39/.40 (Windows, macOS)
  • Google Chrome 155.0.8059.39 (Linux)
  • Distro Chromium packages once fixed versions are published (Debian tracker showed none at time of research)

Immediate actions

  • Update Google Chrome to 155.0.8059.39/.40 (Windows/macOS) or 155.0.8059.39 (Linux) or later and relaunch the browser to apply the update
  • Verify browser version inventory across endpoints and force relaunch where Chrome has been open for long periods
  • Prioritize patching for users with broad web exposure and privileged workstations

Workarounds

  • No vendor workaround cited; restrict browsing to trusted sites and enable enterprise auto-update policies until patched

Longer-term hardening

  • Track Chromium-based browsers (Edge, Brave, Opera, Vivaldi, Electron apps) for downstream releases that include the Chrome 155 fixes
  • Maintain site isolation and sandbox defaults; do not run Chrome with --no-sandbox
  • Use EDR with behavioral detection for browser child-process spawning

CVEs associated with Chrome 155 Update Patches 247 Vulnerabilities Including 4

CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347

Weaknesses (CWE) in Chrome 155 Update Patches 247 Vulnerabilities Including 4

CWE-416

Timeline of Chrome 155 Update Patches 247 Vulnerabilities Including 4

  • Chrome desktop update 154.0.8037.97 released with 11 security fixes, the baseline before the Chrome 155 batch.
  • Chrome Releases blog publishes the Stable Channel Update for Desktop for Chrome 155.
  • Google makes no mention of in-the-wild exploitation of any of the 247 fixes; no public PoC or CVSS scores are cited.
  • SecurityWeek reports Google found the first Critical bug internally, Xinyang Ge reported multiple Critical/High flaws including AI-assisted finds (Google noted it would not reward some AI-found bugs), and external researchers reported 62 fixes with about $33,000 in disclosed bounties.
  • SecurityWeek reports the four Critical use-after-free CVEs (Chromecast, Browser, Navigation, Track); Google makes no mention of in-the-wild exploitation.
  • Chrome 155 (155.0.8059.39/.40 Windows/Mac, 155.0.8059.39 Linux) reported as released with 247 fixes: 4 Critical, 53 High, 122 Medium, 68 Low.
  • Debian security tracker still lists Chromium 150.0.7871.100 and 154.0.8037.92 as vulnerable to the Critical CVEs with no fixed version.
  • Debian tracker for CVE-2026-106382 describes a use-after-free in Chromecast fixed in Chrome 155.0.8059.39, allowing code execution outside the sandbox via a crafted HTML page; bookworm, trixie and forky/sid Chromium remain vulnerable.

Sources cited for Chrome 155 Update Patches 247 Vulnerabilities Including 4

Detection coverage for TL-2026-3251

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3251 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
7 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats