# Multiple Vulnerabilities in Google Chrome (CVE-2026-103621 through CVE-2026-103631) - GovCERT.HK A26-10-08

> Eleven vulnerabilities in Google Chrome prior to 154.0.8037.97 (V8 type confusion, use-after-free in SVG/MediaStream/FedCM/Contextual Tasks, WebGL out-of-bounds write, WebRTC heap overflow, FileSystem authorization flaw and cross-origin leaks) let a remote attacker achieve code execution in or outside the renderer sandbox via a crafted web page. Update to 154.0.8037.97 or later; no in-the-wild exploitation is stated in the sources.

- **Published:** 2026-10-10T15:59:43Z
- **Last reviewed:** 2026-10-10T15:59:43Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3276
- **ID:** TL-2026-3276
- **Severity:** CRITICAL (CVSS 9.6)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 2 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-103621, CVE-2026-103622, CVE-2026-103623, CVE-2026-103624, CVE-2026-103625, CVE-2026-103626, CVE-2026-103627, CVE-2026-103628, CVE-2026-103629, CVE-2026-103630, CVE-2026-103631

## Description

GovCERT.HK alert A26-10-08 (published 2026-10-06) and the HKCERT bulletin (2026-10-05) report eleven vulnerabilities, CVE-2026-103621 through CVE-2026-103631, fixed in the Chrome stable desktop release 154.0.8037.97 (Windows and macOS builds 154.0.8037.97/.98). All versions prior to this release are affected. The attack vector common to all eleven is a remote attacker enticing a user to open a web page containing crafted content (drive-by / user-interaction required). The advisories list four impact classes: remote code execution, denial of service, information disclosure and security restriction bypass.

NVD records (all published 2026-10-02) give the following per-CVE detail. CVE-2026-103621: integer overflow in Compositing allowing cross-origin data access (CVSS 4.3, CWE-190; Chromium issue 556268833). CVE-2026-103622: use after free in SVG, code execution inside the sandbox (CVSS 8.8, CWE-416). CVE-2026-103623: use after free in MediaStream, code execution inside the sandbox (CVSS 8.8, CWE-416). CVE-2026-103624: use after free in Contextual Tasks on Windows, code execution outside the sandbox by an attacker who has already compromised the renderer (CVSS 8.3, CWE-416). CVE-2026-103625: type confusion in V8, code execution inside the sandbox (CVSS 8.8, CWE-843). CVE-2026-103626: incorrect authorization in FileSystem on Windows, potential code execution outside the sandbox via social engineering (CVSS 9.6, CWE-863). CVE-2026-103627: information leak in SVG (CVSS 6.5, CWE-200). CVE-2026-103628: out-of-bounds write in WebGL, code execution outside the sandbox (CVSS 9.6, CWE-787). CVE-2026-103629: integer overflow in Skia leaking cross-origin data (CVSS 4.3, CWE-190). CVE-2026-103630: use after free in FedCM, code execution outside the sandbox (CVSS 9.6, CWE-416). CVE-2026-103631: heap buffer overflow in WebRTC, code execution inside the sandbox (CVSS 8.8, CWE-122).

The renderer-confined bugs (V8, SVG, MediaStream, WebRTC) would typically need to be chained with a sandbox escape for full system compromise; the NVD records for WebGL, FedCM, FileSystem and Contextual Tasks describe impact outside the sandbox directly. The sources do not state active exploitation, a public PoC, or any network or file IOCs, and the CISA KEV feed text that was read (first 100,000 characters of a very large file) showed no entry in this CVE range; the check was not exhaustive. The Chrome Releases blog post for this version could not be retrieved (the fetch returned only the blog index), so reporter credits and bounty details are not included. Severity is set from the highest NVD base score (9.6); HKCERT rates the bulletin Medium risk and GovCERT.HK gives no score. Mitigation is to update via auto-update or Help > About Google Chrome and relaunch the browser.

## MITRE ATT&CK

- T1203 Exploitation for Client Execution
- T1204.001 User Execution: Malicious Link
- T1059.007 Command and Scripting Interpreter: JavaScript

## Sources

- [GovCERT.HK Security Alert (A26-10-08): Multiple Vulnerabilities in Google Chrome](https://www.govcert.gov.hk/en/alerts_detail.php?id=2097)
- [HKCERT Security Bulletin: Google Chrome Multiple Vulnerabilities](https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20261005)
- [Chrome Releases: Stable Channel Update for Desktop (October 2026)](https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html)
- [NVD: CVE-2026-103621 (Compositing integer overflow)](https://nvd.nist.gov/vuln/detail/CVE-2026-103621)
- [NVD: CVE-2026-103626 (FileSystem incorrect authorization)](https://nvd.nist.gov/vuln/detail/CVE-2026-103626)
- [NVD: CVE-2026-103628 (WebGL out-of-bounds write)](https://nvd.nist.gov/vuln/detail/CVE-2026-103628)
- [NVD: CVE-2026-103630 (FedCM use after free)](https://nvd.nist.gov/vuln/detail/CVE-2026-103630)
- [MITRE CVE record: CVE-2026-103621](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-103621)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3276
