# Google Patches 290+ Chrome Flaws

Published: 2026-10-07 · Severity: routine
Canonical: https://vorant.io/reports/4768f67a-855b-5ed2-9cb1-172cab954ad0/google-patches-290-chrome-flaws

> Google fixed over 290 Chrome vulnerabilities, including many use-after-free and type confusion bugs, with no known in-the-wild exploitation yet.

MS-ISAC advisory 2026-109 details an unusually large batch of vulnerabilities patched in Google Chrome versions prior to 155.0.8059.39/.40 (Windows/Mac) and 155.0.8059.39 (Linux). The flaws span nearly every Chrome subsystem including V8, ANGLE, Media, WebRTC, PDF, Fonts, Autofill, DevTools, and the sandbox itself, with the predominant bug classes being use-after-free, type confusion, race conditions, integer/buffer overflows, and various incorrect/missing authorization checks. The most severe issues could allow arbitrary code execution in the context of the logged-on user, potentially enabling an attacker to install programs, modify or delete data, or create new accounts with full privileges if the victim is running with administrative rights.

MS-ISAC states there are no current reports of in-the-wild exploitation for any of these vulnerabilities, and classifies the primary attack vector as drive-by compromise (requiring a user to visit a malicious or compromised page, or interact with malicious content). Given the sheer number of memory-corruption-class bugs (use-after-free, type confusion, heap overflow) in core rendering and JavaScript engine components, and a privilege-elevation flaw in the sandbox itself, the risk of a chained RCE exploit is non-trivial once technical details circulate, even though nothing is confirmed exploited today.

Defenders should prioritize rolling out the Chrome update broadly and promptly via automated patch management, since browsers are a primary initial-access surface. Standard hardening measures apply: enforce least-privilege (non-admin) browsing accounts, enable OS/browser anti-exploitation features (DEP, Exploit Guard, SIP/Gatekeeper), apply DNS/URL filtering, and reinforce user awareness against malicious links and attachments, as several of these bugs are reachable via normal web browsing.

## Mentioned in this report

- Vulnerabilities: CVE-2026-102322, CVE-2026-106190, CVE-2026-106193, CVE-2026-106197, CVE-2026-106200, CVE-2026-106201, CVE-2026-106204, CVE-2026-106207, CVE-2026-106211, CVE-2026-106227, CVE-2026-106233, CVE-2026-106235, CVE-2026-106239, CVE-2026-106240, CVE-2026-106248, CVE-2026-106255, CVE-2026-106257, CVE-2026-106268, CVE-2026-106278, CVE-2026-106281, CVE-2026-106292, CVE-2026-106293, CVE-2026-106298, CVE-2026-106318, CVE-2026-106332, CVE-2026-106335, CVE-2026-106341, CVE-2026-106347, CVE-2026-106349, CVE-2026-106357, CVE-2026-106358, CVE-2026-106374, CVE-2026-106378, CVE-2026-106382, CVE-2026-106383, CVE-2026-106393, CVE-2026-106411, CVE-2026-106419, CVE-2026-106421, CVE-2026-106423

## Detection guidance (public sample)

### Chrome Browser Spawning Script Interpreter or LOLBin

ATT&CK: T1189

Chrome spawning cmd, PowerShell, WSH, mshta, rundll32 or similar download/exec binaries may indicate post-exploitation after a drive-by browser exploit. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Chrome Browser Spawning Script Interpreter or LOLBin
description: Detects chrome.exe directly spawning shells, script hosts or common LOLBins.
  After a successful renderer/V8 exploit and sandbox escape, payload staging often
  starts as a child of the browser process. Generalises on the parent/child relation,
  not any specific exploit or URL.
tags:
- attack.initial-access
- attack.t1189
- attack.execution
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith: \chrome.exe
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
    - \wscript.exe
    - \cscript.exe
    - \mshta.exe
    - \rundll32.exe
    - \regsvr32.exe
    - \certutil.exe
    - \bitsadmin.exe
    - \msiexec.exe
  filter_native_messaging:
    CommandLine|contains: chrome-extension://
  condition: selection and not filter_native_messaging
falsepositives:
- Browser extensions or native messaging hosts that launch helper scripts via cmd.exe
- Enterprise web apps using custom URL handlers that launch a shell through Chrome
level: medium
id: 54fce124-a4a1-52fc-95ff-58b9babc7a05
status: experimental
author: Vorant
references:
- https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-109
```

### Chrome Child Process Running With SYSTEM Privileges

ATT&CK: T1068

A process spawned by chrome.exe running at SYSTEM integrity or as SYSTEM suggests a sandbox escape or local privilege escalation. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Chrome Child Process Running With SYSTEM Privileges
description: Detects processes whose parent is chrome.exe but which run at System
  integrity or as NT AUTHORITY\SYSTEM. Chrome and its renderers run as the logged-on
  user, so a SYSTEM child is a strong sign of a sandbox escape or privilege-escalation
  exploit. Requires Sysmon-style IntegrityLevel/User telemetry.
tags:
- attack.privilege-escalation
- attack.t1068
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: \chrome.exe
  selection_priv_il:
    IntegrityLevel: System
  selection_priv_user:
    User|contains:
    - AUTHORITY\SYSTEM
    - "NT-AUTORIT\xC4T\\SYSTEM"
  condition: selection_parent and 1 of selection_priv_*
falsepositives:
- Chrome installer or updater components launched under SYSTEM by software deployment
  tooling that appear with chrome.exe as parent
level: high
id: a5b1eaea-cb22-564c-b2e7-56111b3eca4a
status: experimental
author: Vorant
references:
- https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-109
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-109

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4768f67a-855b-5ed2-9cb1-172cab954ad0/google-patches-290-chrome-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
