VORANT. Threat Intelligence Research Sign in Create a free account

Google Patches 290+ Chrome Flaws

routine vulnerability

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Google fixed over 290 Chrome vulnerabilities, including many use-after-free and type confusion bugs, with no known in-the-wild exploitation yet.

MS-ISAC advisory 2026-109 details an unusually large batch of vulnerabilities patched in Google Chrome versions prior to 155.0.8059.39/.40 (Windows/Mac) and 155.0.8059.39 (Linux). The flaws span nearly every Chrome subsystem including V8, ANGLE, Media, WebRTC, PDF, Fonts, Autofill, DevTools, and the sandbox itself, with the predominant bug classes being use-after-free, type confusion, race conditions, integer/buffer overflows, and various incorrect/missing authorization checks. The most severe issues could allow arbitrary code execution in the context of the logged-on user, potentially enabling an attacker to install programs, modify or delete data, or create new accounts with full privileges if the victim is running with administrative rights.

MS-ISAC states there are no current reports of in-the-wild exploitation for any of these vulnerabilities, and classifies the primary attack vector as drive-by compromise (requiring a user to visit a malicious or compromised page, or interact with malicious content). Given the sheer number of memory-corruption-class bugs (use-after-free, type confusion, heap overflow) in core rendering and JavaScript engine components, and a privilege-elevation flaw in the sandbox itself, the risk of a chained RCE exploit is non-trivial once technical details circulate, even though nothing is confirmed exploited today.

Defenders should prioritize rolling out the Chrome update broadly and promptly via automated patch management, since browsers are a primary initial-access surface. Standard hardening measures apply: enforce least-privilege (non-admin) browsing accounts, enable OS/browser anti-exploitation features (DEP, Exploit Guard, SIP/Gatekeeper), apply DNS/URL filtering, and reinforce user awareness against malicious links and attachments, as several of these bugs are reachable via normal web browsing.

Mentioned in this report

Vulnerabilities CVE-2026-102322CVE-2026-106190CVE-2026-106193CVE-2026-106197CVE-2026-106200CVE-2026-106201CVE-2026-106204CVE-2026-106207CVE-2026-106211CVE-2026-106227CVE-2026-106233CVE-2026-106235CVE-2026-106239CVE-2026-106240CVE-2026-106248CVE-2026-106255CVE-2026-106257CVE-2026-106268CVE-2026-106278CVE-2026-106281CVE-2026-106292CVE-2026-106293CVE-2026-106298CVE-2026-106318CVE-2026-106332CVE-2026-106335CVE-2026-106341CVE-2026-106347CVE-2026-106349CVE-2026-106357CVE-2026-106358CVE-2026-106374CVE-2026-106378CVE-2026-106382CVE-2026-106383CVE-2026-106393CVE-2026-106411CVE-2026-106419CVE-2026-106421CVE-2026-106423

Detection guidance

Chrome Browser Spawning Script Interpreter or LOLBin

ATT&CK T1189

Chrome spawning cmd, PowerShell, WSH, mshta, rundll32 or similar download/exec binaries may indicate post-exploitation after a drive-by browser exploit. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Chrome Browser Spawning Script Interpreter or LOLBin
description: Detects chrome.exe directly spawning shells, script hosts or common LOLBins.
  After a successful renderer/V8 exploit and sandbox escape, payload staging often
  starts as a child of the browser process. Generalises on the parent/child relation,
  not any specific exploit or URL.
tags:
- attack.initial-access
- attack.t1189
- attack.execution
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith: \chrome.exe
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
    - \wscript.exe
    - \cscript.exe
    - \mshta.exe
    - \rundll32.exe
    - \regsvr32.exe
    - \certutil.exe
    - \bitsadmin.exe
    - \msiexec.exe
  filter_native_messaging:
    CommandLine|contains: chrome-extension://
  condition: selection and not filter_native_messaging
falsepositives:
- Browser extensions or native messaging hosts that launch helper scripts via cmd.exe
- Enterprise web apps using custom URL handlers that launch a shell through Chrome
level: medium
id: 54fce124-a4a1-52fc-95ff-58b9babc7a05
status: experimental
author: Vorant
references:
- https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-109

Chrome Child Process Running With SYSTEM Privileges

ATT&CK T1068

A process spawned by chrome.exe running at SYSTEM integrity or as SYSTEM suggests a sandbox escape or local privilege escalation. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Chrome Child Process Running With SYSTEM Privileges
description: Detects processes whose parent is chrome.exe but which run at System
  integrity or as NT AUTHORITY\SYSTEM. Chrome and its renderers run as the logged-on
  user, so a SYSTEM child is a strong sign of a sandbox escape or privilege-escalation
  exploit. Requires Sysmon-style IntegrityLevel/User telemetry.
tags:
- attack.privilege-escalation
- attack.t1068
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: \chrome.exe
  selection_priv_il:
    IntegrityLevel: System
  selection_priv_user:
    User|contains:
    - AUTHORITY\SYSTEM
    - "NT-AUTORIT\xC4T\\SYSTEM"
  condition: selection_parent and 1 of selection_priv_*
falsepositives:
- Chrome installer or updater components launched under SYSTEM by software deployment
  tooling that appear with chrome.exe as parent
level: high
id: a5b1eaea-cb22-564c-b2e7-56111b3eca4a
status: experimental
author: Vorant
references:
- https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-109

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-109

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,868 reports from 149 sources, 447 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs