Threat reportVulnerabilityTL-2026-3251
Chrome 155 Update Patches 247 Vulnerabilities Including 4 Critical Use-After-Free Flaws (CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347)
Chrome 155 Update Patches 247 Vulnerabilities Including 4 (TL-2026-3251), also tracked as Chrome 155 security update, is a critical-severity software vulnerability, first published 2026-10-10. It has no confirmed attribution, affects Google Chrome (Windows, macOS, Linux), references 4 CVEs (CVE-2026-106382, CVE-2026-106197, CVE-2026-106358), maps to 2 MITRE ATT&CK techniques (T1203, T1204.001), and is covered by 9 detection rules and 7 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 4Referenced vulnerabilities
- Techniques
- 2MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 7Indicators of compromise
Key facts for TL-2026-3251
- Threat ID
- TL-2026-3251
- Also known as
- Chrome 155 security update, Chrome 155.0.8059.39
- Severity
- CRITICAL
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all sectors, enterprise, government administration, consumer
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 7
How Chrome 155 Update Patches 247 Vulnerabilities Including 4 works
Google released Chrome 155 (155.0.8059.39/.40 for Windows/macOS, 155.0.8059.39 for Linux) fixing 247 security issues: 4 Critical, 53 High, 122 Medium and 68 Low. The four Critical flaws are use-after-free bugs in Chromecast, Browser, Navigation and Track; Google does not report exploitation in the wild.
On 2026-10-06/07 Google promoted Chrome 155 to the Stable channel with 247 security fixes, far above recent cadence (the 2026-10-01 desktop update 154.0.8037.97 contained 11 fixes). Fixed builds are 155.0.8059.39/.40 on Windows and macOS and 155.0.8059.39 on Linux, rolling out over days to weeks, with corresponding mobile releases.
Four bugs are rated Critical by the Chromium security team, all use-after-free (CWE-416): CVE-2026-106382 (Chromecast), CVE-2026-106197 (Browser), CVE-2026-106358 (Navigation) and CVE-2026-106347 (Track). Per the Debian security tracker, CVE-2026-106382, CVE-2026-106197 and CVE-2026-106358 allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page (i.e. a sandbox escape), while CVE-2026-106347 allows code execution inside the sandbox via a crafted HTML page. Chrome versions prior to 155.0.8059.39 are affected.
Per SecurityWeek, Google discovered the first Critical bug internally; researcher Xinyang Ge reported three Critical flaws and used AI to identify two additional defects. External researchers reported 62 of the fixes, with roughly $33,000 in bounties disclosed and nearly 50 reports lacking published reward amounts. The most common categories across the batch were incorrect authorization (41), use-after-free (34), missing authorization (34), UI misrepresentation (20) and information leak (17).
Google makes no mention of in-the-wild exploitation, no public PoC is cited in the sources, and no CVSS scores or detailed attack vectors were published at the time of research. This is a patch-prioritization item for a widely deployed browser rather than an active-exploitation campaign. As of the Debian tracker snapshot, distro Chromium packages (150.0.7871.100 and 154.0.8037.92 in bookworm, trixie, forky, sid) were still listed as vulnerable with no fixed version.
MITRE ATT&CK techniques used in TL-2026-3251
Execution
T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link
Affected products and versions in Chrome 155 Update Patches 247 Vulnerabilities Including 4
Remediation for Chrome 155 Update Patches 247 Vulnerabilities Including 4
Patches
- Google Chrome 155.0.8059.39/.40 (Windows, macOS)
- Google Chrome 155.0.8059.39 (Linux)
- Distro Chromium packages once fixed versions are published (Debian tracker showed none at time of research)
Immediate actions
- Update Google Chrome to 155.0.8059.39/.40 (Windows/macOS) or 155.0.8059.39 (Linux) or later and relaunch the browser to apply the update
- Verify browser version inventory across endpoints and force relaunch where Chrome has been open for long periods
- Prioritize patching for users with broad web exposure and privileged workstations
Workarounds
- No vendor workaround cited; restrict browsing to trusted sites and enable enterprise auto-update policies until patched
Longer-term hardening
- Track Chromium-based browsers (Edge, Brave, Opera, Vivaldi, Electron apps) for downstream releases that include the Chrome 155 fixes
- Maintain site isolation and sandbox defaults; do not run Chrome with --no-sandbox
- Use EDR with behavioral detection for browser child-process spawning
CVEs associated with Chrome 155 Update Patches 247 Vulnerabilities Including 4
CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347
Weaknesses (CWE) in Chrome 155 Update Patches 247 Vulnerabilities Including 4
Timeline of Chrome 155 Update Patches 247 Vulnerabilities Including 4
- Chrome desktop update 154.0.8037.97 released with 11 security fixes, the baseline before the Chrome 155 batch.
- Chrome Releases blog publishes the Stable Channel Update for Desktop for Chrome 155.
- Google makes no mention of in-the-wild exploitation of any of the 247 fixes; no public PoC or CVSS scores are cited.
- SecurityWeek reports Google found the first Critical bug internally, Xinyang Ge reported multiple Critical/High flaws including AI-assisted finds (Google noted it would not reward some AI-found bugs), and external researchers reported 62 fixes with about $33,000 in disclosed bounties.
- SecurityWeek reports the four Critical use-after-free CVEs (Chromecast, Browser, Navigation, Track); Google makes no mention of in-the-wild exploitation.
- Chrome 155 (155.0.8059.39/.40 Windows/Mac, 155.0.8059.39 Linux) reported as released with 247 fixes: 4 Critical, 53 High, 122 Medium, 68 Low.
- Debian security tracker still lists Chromium 150.0.7871.100 and 154.0.8037.92 as vulnerable to the Critical CVEs with no fixed version.
- Debian tracker for CVE-2026-106382 describes a use-after-free in Chromecast fixed in Chrome 155.0.8059.39, allowing code execution outside the sandbox via a crafted HTML page; bookworm, trixie and forky/sid Chromium remain vulnerable.
Sources cited for Chrome 155 Update Patches 247 Vulnerabilities Including 4
- Chrome 155 Update Patches 247 Vulnerabilities (SecurityWeek)
- Stable Channel Update for Desktop (Chrome Releases)
- Google releases Chrome 155 with 247 security fixes, four of them rated critical (BleepingComputer)
- Debian Security Tracker: CVE-2026-106382
- Debian Security Tracker: CVE-2026-106197
- Debian Security Tracker: CVE-2026-106358
- Debian Security Tracker: CVE-2026-106347
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-3251
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3251 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.