Threat reportVulnerabilityTL-2026-3276

Multiple Vulnerabilities in Google Chrome (CVE-2026-103621 through CVE-2026-103631) - GovCERT.HK A26-10-08

criticalPATCHED

Multiple Vulnerabilities in Google Chrome (CVE-2026-103621 (TL-2026-3276), also tracked as GovCERT.HK A26-10-08, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-10. It has no confirmed attribution, affects Google Chrome (Windows, macOS, Linux), references 11 CVEs (CVE-2026-103621, CVE-2026-103622, CVE-2026-103623), maps to 3 MITRE ATT&CK techniques (T1059.007, T1203, T1204.001), and is covered by 9 detection rules and 2 indicators of compromise.

CVSS
9.6/10Critical
CVEs
11Referenced vulnerabilities
Techniques
3MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
2Indicators of compromise

Key facts for TL-2026-3276

Threat ID
TL-2026-3276
Also known as
GovCERT.HK A26-10-08
Severity
CRITICAL
CVSS
9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, education
Target regions
Global
Detection rules
9
Indicators of compromise
2

How Multiple Vulnerabilities in Google Chrome (CVE-2026-103621 works

Eleven vulnerabilities in Google Chrome prior to 154.0.8037.97 (V8 type confusion, use-after-free in SVG/MediaStream/FedCM/Contextual Tasks, WebGL out-of-bounds write, WebRTC heap overflow, FileSystem authorization flaw and cross-origin leaks) let a remote attacker achieve code execution in or outside the renderer sandbox via a crafted web page. Update to 154.0.8037.97 or later; no in-the-wild exploitation is stated in the sources.

GovCERT.HK alert A26-10-08 (published 2026-10-06) and the HKCERT bulletin (2026-10-05) report eleven vulnerabilities, CVE-2026-103621 through CVE-2026-103631, fixed in the Chrome stable desktop release 154.0.8037.97 (Windows and macOS builds 154.0.8037.97/.98). All versions prior to this release are affected. The attack vector common to all eleven is a remote attacker enticing a user to open a web page containing crafted content (drive-by / user-interaction required). The advisories list four impact classes: remote code execution, denial of service, information disclosure and security restriction bypass.

NVD records (all published 2026-10-02) give the following per-CVE detail. CVE-2026-103621: integer overflow in Compositing allowing cross-origin data access (CVSS 4.3, CWE-190; Chromium issue 556268833). CVE-2026-103622: use after free in SVG, code execution inside the sandbox (CVSS 8.8, CWE-416). CVE-2026-103623: use after free in MediaStream, code execution inside the sandbox (CVSS 8.8, CWE-416). CVE-2026-103624: use after free in Contextual Tasks on Windows, code execution outside the sandbox by an attacker who has already compromised the renderer (CVSS 8.3, CWE-416). CVE-2026-103625: type confusion in V8, code execution inside the sandbox (CVSS 8.8, CWE-843). CVE-2026-103626: incorrect authorization in FileSystem on Windows, potential code execution outside the sandbox via social engineering (CVSS 9.6, CWE-863). CVE-2026-103627: information leak in SVG (CVSS 6.5, CWE-200). CVE-2026-103628: out-of-bounds write in WebGL, code execution outside the sandbox (CVSS 9.6, CWE-787). CVE-2026-103629: integer overflow in Skia leaking cross-origin data (CVSS 4.3, CWE-190). CVE-2026-103630: use after free in FedCM, code execution outside the sandbox (CVSS 9.6, CWE-416). CVE-2026-103631: heap buffer overflow in WebRTC, code execution inside the sandbox (CVSS 8.8, CWE-122).

The renderer-confined bugs (V8, SVG, MediaStream, WebRTC) would typically need to be chained with a sandbox escape for full system compromise; the NVD records for WebGL, FedCM, FileSystem and Contextual Tasks describe impact outside the sandbox directly. The sources do not state active exploitation, a public PoC, or any network or file IOCs, and the CISA KEV feed text that was read (first 100,000 characters of a very large file) showed no entry in this CVE range; the check was not exhaustive. The Chrome Releases blog post for this version could not be retrieved (the fetch returned only the blog index), so reporter credits and bounty details are not included. Severity is set from the highest NVD base score (9.6); HKCERT rates the bulletin Medium risk and GovCERT.HK gives no score. Mitigation is to update via auto-update or Help > About Google Chrome and relaunch the browser.

MITRE ATT&CK techniques used in TL-2026-3276

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link

Affected products and versions in Multiple Vulnerabilities in Google Chrome (CVE-2026-103621

  • Google — Chrome (Windows, macOS, Linux)
    Vulnerable versions: Prior to 154.0.8037.97
    Fixed in: 154.0.8037.97 (Linux); 154.0.8037.97/.98 (Windows, macOS)

Remediation for Multiple Vulnerabilities in Google Chrome (CVE-2026-103621

Patches

  • Google Chrome 154.0.8037.97 (Linux) / 154.0.8037.97/.98 (Windows, macOS)

Immediate actions

  • Update Google Chrome to 154.0.8037.97 or later (Windows/macOS 154.0.8037.97/.98) via auto-update or Help > About Google Chrome, then relaunch the browser
  • Verify fleet-wide Chrome version inventory and flag endpoints running versions prior to 154.0.8037.97

Workarounds

  • No vendor workaround is stated in the sources; restrict browsing of untrusted sites until patched

Longer-term hardening

  • Enforce managed Chrome auto-update policies and a short patch SLA for browser releases
  • Keep Chrome renderer sandbox and Site Isolation enabled and monitor for child-process anomalies from chrome.exe
  • Deploy EDR coverage for browser-spawned process chains

CVEs associated with Multiple Vulnerabilities in Google Chrome (CVE-2026-103621

CVE-2026-103621, CVE-2026-103622, CVE-2026-103623, CVE-2026-103624, CVE-2026-103625, CVE-2026-103626, CVE-2026-103627, CVE-2026-103628, CVE-2026-103629, CVE-2026-103630, CVE-2026-103631

Weaknesses (CWE) in Multiple Vulnerabilities in Google Chrome (CVE-2026-103621

CWE-190, CWE-416, CWE-843, CWE-863, CWE-200, CWE-787, CWE-122

Timeline of Multiple Vulnerabilities in Google Chrome (CVE-2026-103621

  • Prior Chrome 154 stable build 154.0.8037.57/.58 shipped (per Chrome Releases search results); it is below the fixed version and therefore vulnerable.
  • Chrome Releases blog (page header dated Thursday, October 1, 2026) carries the stable desktop update to 154.0.8037.97; secondary reporting describes it as an 11-fix security update.
  • NVD records assign CVSS 3.1 base scores from 4.3 to 9.6; WebGL (CVE-2026-103628), FedCM (CVE-2026-103630) and FileSystem (CVE-2026-103626) are scored 9.6 with sandbox-escape impact.
  • NVD publishes CVE-2026-103621 through CVE-2026-103631, all stating Chrome prior to 154.0.8037.97 is affected.
  • HKCERT publishes bulletin rating the issues Medium risk and listing Windows/macOS fixed builds 154.0.8037.97/.98.
  • GovCERT.HK publishes Security Alert A26-10-08 urging users to update Chrome to 154.0.8037.97 or later.

Sources cited for Multiple Vulnerabilities in Google Chrome (CVE-2026-103621

Detection coverage for TL-2026-3276

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3276 across Splunk SPL, Microsoft KQL and Sigma, covering 2 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
2 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats