Threat reportVulnerabilityTL-2026-3276
Multiple Vulnerabilities in Google Chrome (CVE-2026-103621 through CVE-2026-103631) - GovCERT.HK A26-10-08
Multiple Vulnerabilities in Google Chrome (CVE-2026-103621 (TL-2026-3276), also tracked as GovCERT.HK A26-10-08, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-10. It has no confirmed attribution, affects Google Chrome (Windows, macOS, Linux), references 11 CVEs (CVE-2026-103621, CVE-2026-103622, CVE-2026-103623), maps to 3 MITRE ATT&CK techniques (T1059.007, T1203, T1204.001), and is covered by 9 detection rules and 2 indicators of compromise.
- CVSS
- 9.6/10Critical
- CVEs
- 11Referenced vulnerabilities
- Techniques
- 3MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 2Indicators of compromise
Key facts for TL-2026-3276
- Threat ID
- TL-2026-3276
- Also known as
- GovCERT.HK A26-10-08
- Severity
- CRITICAL
- CVSS
- 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 2
How Multiple Vulnerabilities in Google Chrome (CVE-2026-103621 works
Eleven vulnerabilities in Google Chrome prior to 154.0.8037.97 (V8 type confusion, use-after-free in SVG/MediaStream/FedCM/Contextual Tasks, WebGL out-of-bounds write, WebRTC heap overflow, FileSystem authorization flaw and cross-origin leaks) let a remote attacker achieve code execution in or outside the renderer sandbox via a crafted web page. Update to 154.0.8037.97 or later; no in-the-wild exploitation is stated in the sources.
GovCERT.HK alert A26-10-08 (published 2026-10-06) and the HKCERT bulletin (2026-10-05) report eleven vulnerabilities, CVE-2026-103621 through CVE-2026-103631, fixed in the Chrome stable desktop release 154.0.8037.97 (Windows and macOS builds 154.0.8037.97/.98). All versions prior to this release are affected. The attack vector common to all eleven is a remote attacker enticing a user to open a web page containing crafted content (drive-by / user-interaction required). The advisories list four impact classes: remote code execution, denial of service, information disclosure and security restriction bypass.
NVD records (all published 2026-10-02) give the following per-CVE detail. CVE-2026-103621: integer overflow in Compositing allowing cross-origin data access (CVSS 4.3, CWE-190; Chromium issue 556268833). CVE-2026-103622: use after free in SVG, code execution inside the sandbox (CVSS 8.8, CWE-416). CVE-2026-103623: use after free in MediaStream, code execution inside the sandbox (CVSS 8.8, CWE-416). CVE-2026-103624: use after free in Contextual Tasks on Windows, code execution outside the sandbox by an attacker who has already compromised the renderer (CVSS 8.3, CWE-416). CVE-2026-103625: type confusion in V8, code execution inside the sandbox (CVSS 8.8, CWE-843). CVE-2026-103626: incorrect authorization in FileSystem on Windows, potential code execution outside the sandbox via social engineering (CVSS 9.6, CWE-863). CVE-2026-103627: information leak in SVG (CVSS 6.5, CWE-200). CVE-2026-103628: out-of-bounds write in WebGL, code execution outside the sandbox (CVSS 9.6, CWE-787). CVE-2026-103629: integer overflow in Skia leaking cross-origin data (CVSS 4.3, CWE-190). CVE-2026-103630: use after free in FedCM, code execution outside the sandbox (CVSS 9.6, CWE-416). CVE-2026-103631: heap buffer overflow in WebRTC, code execution inside the sandbox (CVSS 8.8, CWE-122).
The renderer-confined bugs (V8, SVG, MediaStream, WebRTC) would typically need to be chained with a sandbox escape for full system compromise; the NVD records for WebGL, FedCM, FileSystem and Contextual Tasks describe impact outside the sandbox directly. The sources do not state active exploitation, a public PoC, or any network or file IOCs, and the CISA KEV feed text that was read (first 100,000 characters of a very large file) showed no entry in this CVE range; the check was not exhaustive. The Chrome Releases blog post for this version could not be retrieved (the fetch returned only the blog index), so reporter credits and bounty details are not included. Severity is set from the highest NVD base score (9.6); HKCERT rates the bulletin Medium risk and GovCERT.HK gives no score. Mitigation is to update via auto-update or Help > About Google Chrome and relaunch the browser.
MITRE ATT&CK techniques used in TL-2026-3276
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link
Affected products and versions in Multiple Vulnerabilities in Google Chrome (CVE-2026-103621
- Google — Chrome (Windows, macOS, Linux)
Vulnerable versions: Prior to 154.0.8037.97
Fixed in: 154.0.8037.97 (Linux); 154.0.8037.97/.98 (Windows, macOS)
Remediation for Multiple Vulnerabilities in Google Chrome (CVE-2026-103621
Patches
- Google Chrome 154.0.8037.97 (Linux) / 154.0.8037.97/.98 (Windows, macOS)
Immediate actions
- Update Google Chrome to 154.0.8037.97 or later (Windows/macOS 154.0.8037.97/.98) via auto-update or Help > About Google Chrome, then relaunch the browser
- Verify fleet-wide Chrome version inventory and flag endpoints running versions prior to 154.0.8037.97
Workarounds
- No vendor workaround is stated in the sources; restrict browsing of untrusted sites until patched
Longer-term hardening
- Enforce managed Chrome auto-update policies and a short patch SLA for browser releases
- Keep Chrome renderer sandbox and Site Isolation enabled and monitor for child-process anomalies from chrome.exe
- Deploy EDR coverage for browser-spawned process chains
CVEs associated with Multiple Vulnerabilities in Google Chrome (CVE-2026-103621
CVE-2026-103621, CVE-2026-103622, CVE-2026-103623, CVE-2026-103624, CVE-2026-103625, CVE-2026-103626, CVE-2026-103627, CVE-2026-103628, CVE-2026-103629, CVE-2026-103630, CVE-2026-103631
Weaknesses (CWE) in Multiple Vulnerabilities in Google Chrome (CVE-2026-103621
CWE-190, CWE-416, CWE-843, CWE-863, CWE-200, CWE-787, CWE-122
Timeline of Multiple Vulnerabilities in Google Chrome (CVE-2026-103621
- Prior Chrome 154 stable build 154.0.8037.57/.58 shipped (per Chrome Releases search results); it is below the fixed version and therefore vulnerable.
- Chrome Releases blog (page header dated Thursday, October 1, 2026) carries the stable desktop update to 154.0.8037.97; secondary reporting describes it as an 11-fix security update.
- NVD records assign CVSS 3.1 base scores from 4.3 to 9.6; WebGL (CVE-2026-103628), FedCM (CVE-2026-103630) and FileSystem (CVE-2026-103626) are scored 9.6 with sandbox-escape impact.
- NVD publishes CVE-2026-103621 through CVE-2026-103631, all stating Chrome prior to 154.0.8037.97 is affected.
- HKCERT publishes bulletin rating the issues Medium risk and listing Windows/macOS fixed builds 154.0.8037.97/.98.
- GovCERT.HK publishes Security Alert A26-10-08 urging users to update Chrome to 154.0.8037.97 or later.
Sources cited for Multiple Vulnerabilities in Google Chrome (CVE-2026-103621
- GovCERT.HK Security Alert (A26-10-08): Multiple Vulnerabilities in Google Chrome
- HKCERT Security Bulletin: Google Chrome Multiple Vulnerabilities
- Chrome Releases: Stable Channel Update for Desktop (October 2026)
- NVD: CVE-2026-103621 (Compositing integer overflow)
- NVD: CVE-2026-103626 (FileSystem incorrect authorization)
- NVD: CVE-2026-103628 (WebGL out-of-bounds write)
- NVD: CVE-2026-103630 (FedCM use after free)
- MITRE CVE record: CVE-2026-103621
Detection coverage for TL-2026-3276
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3276 across Splunk SPL, Microsoft KQL and Sigma, covering 2 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.