Skip to content
Brief Security & Trust ·

HKCERT flags multiple security flaws in Google Chrome for desktop

Hong Kong's emergency response team lists several flaws and says Chrome 155.0.8059.39 or later is not affected.

In brief
  • HKCERT says several Chrome flaws could let a remote attacker run code or steal data. Linux, Mac and Windows builds are affected.
  • The bulletin gives no CVE numbers, flaw count or severity, and does not say if attacks are happening.

HKCERT, Hong Kong's computer emergency response team, said on 7 October 2026 that Google Chrome has several security flaws. It said a remote attacker could use some of them against a target system. The possible results include remote code execution, which means running the attacker's own code. They also include crashes, data theft, data changes and spoofing, which means faking a trusted page. Affected versions are Linux builds before 155.0.8059.39, and Mac and Windows builds before 155.0.8059.39/.40. HKCERT lists those numbers, or anything newer, as the safe versions.

The bulletin leaves many points open. It gives no CVE numbers, which are the public IDs for single flaws. It does not say how many flaws there are or how severe each one is. It does not link each flaw to a specific result. It also does not say whether attackers are using any of them now. HKCERT points readers to Google's Chrome release notes and advises checking the vendor's site before installing.

Teams that manage company laptops, or that test sites and apps in Chrome, can check installed versions against 155.0.8059.39. HKCERT names fixed builds for all three desktop systems, so the version number shows who is still exposed.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: HKCERT.