Google Chrome 154 patches 32 flaws including critical ANGLE buffer overflow CVE-2026-102331 and multiple V8 type-confusion bugs; no active exploitation reported.
Google released Chrome 154 (154.0.8037.92/.93 for Windows and macOS, .92 for Linux) fixing 32 vulnerabilities, headlined by critical ANGLE buffer overflow CVE-2026-102331. The update also patches 25 high-severity flaws across V8, GPU, WebGPU, WebGL, Mojo, Bluetooth, Dawn, Skia, Views, and media components, including several V8 type-confusion bugs (CVE-2026-102299, CVE-2026-102321, CVE-2026-102323, CVE-2026-102326, CVE-2026-102328). Google has not indicated any active exploitation and is withholding technical details until most users have updated.
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-102304 | Use-after-free in Chrome Passwords allows sandbox escape Google Chrome versions before 154.0.8037.92 contain a use-after-free flaw (CWE-416) in the Passwords component. A remote attacker can trigger it by getting a user to open a crafted HTML page, then execute arbitrary code outside the browser sandbox. The issue needs no prior privileges and is rated High by Chromium, with a CVSS 3.1 base score of 9.6 (network, low complexity, user interaction required, changed scope, high confidentiality, integrity, and availability impact). Anyone still running an unpatched Chrome build older than 154.0.8037.92 is affected. It is not listed in CISA KEV, and no public proof-of-concept is known. Do: Update Google Chrome to version 154.0.8037.92 or later on all user and managed endpoints, and confirm the running build via chrome://settings/help. Prioritize machines that browse untrusted web content. No workaround is described in the advisory, so treat any earlier build as exposed to remote code execution if a user opens a malicious page. | 9.6 group max | — |
| masson the order of 1–3 billion Chrome users until updated past 154.0.8037.92 |
Google has released Chrome version 154 for desktop platforms, addressing 32 security vulnerabilities, including a critical buffer overflow flaw in the ANGLE graphics translation layer.
This update is being rolled out as version 154.0.8037.92/.93 for Windows and macOS, and version 154.0.8037.92 for Linux.
The most severe issue, tracked as CVE-2026-102331, is a critical buffer overflow in ANGLE, which is a Chromium component that translates graphics APIs like OpenGL ES to platform-native graphics interfaces.
Google has not yet released technical details or an exploit scenario as a precaution, allowing users time to install the fixed version before the vulnerability details become widely known.
Chrome version 154 also addresses 25 high-severity flaws across several components, including the V8 JavaScript and WebAssembly engine, GPU, WebGPU, WebGL, Mojo, Bluetooth, Passwords, Views, WebUI, Dawn, Skia, and media processing.
Several of these serious bugs are memory safety issues, such as type confusion, use-after-free, buffer overflow, out-of-bounds write, and uninitialized resource defects, which can be exploited in browser attacks.
Notably, the release includes four high-severity type-confusion vulnerabilities in V8: CVE-2026-102299, CVE-2026-102323, CVE-2026-102326, CVE-2026-102328, and CVE-2026-102321.
Type-confusion bugs in V8 are particularly concerning because JavaScript parsing and execution occur when users visit web content. However, Google has not indicated that any of these flaws are currently being actively exploited.
OpenAI Codex Security researcher “amyb” reported three of the V8 type-confusion issues, while researcher Taisic Yun from Theori, collaborating with Xint, reported CVE-2026-102321. Other findings came from independent researchers, Google’s internal teams, and external security organizations.
Google stated that some bug reports and issue-tracker links will remain restricted until most Chrome users have received the update. This period may be extended if a vulnerable third-party dependency remains unpatched in other projects.
The company credited AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL for identifying security defects during development.
CVE Details
| CVE | Severity | Component | Vulnerability type | Reporter |
|---|---|---|---|---|
| CVE-2026-102331 | Critical | ANGLE | Buffer overflow | @mfx |
| CVE-2026-102317 | High | Mojo | Improper privilege management | |
| CVE-2026-102312 | High | Omnibox | UI misrepresentation | jodyritonga |
| CVE-2026-102313 | High | ANGLE | Uninitialized resource | |
| CVE-2026-102299 | High | V8 | Type confusion | Andrew Boni |
| CVE-2026-102306 | High | Bluetooth | Use-after-free | |
| CVE-2026-102307 | High | Dawn | Uninitialized resource | |
| CVE-2026-102323 | High | V8 | Type confusion | OpenAI Codex Security |
| CVE-2026-102303 | High | GPU | Uninitialized resource | |
| CVE-2026-102311 | High | GPU | Uninitialized resource | |
| CVE-2026-102300 | High | WebGPU | Uninitialized resource | Arni Hardarson, Neonix Security |
| CVE-2026-102326 | High | V8 | Type confusion | OpenAI Codex Security |
| CVE-2026-102316 | High | Views | Use-after-free | Xinyang Ge |
| CVE-2026-102304 | High | Passwords | Use-after-free | Xinyang Ge |
| CVE-2026-102328 | High | V8 | Type confusion | OpenAI Codex Security |
| CVE-2026-102309 | High | FullScreen | Use-after-free | sean geofrey |
| CVE-2026-102325 | High | Skia | Uninitialized resource | |
| CVE-2026-102308 | High | Views | Use-after-free | |
| CVE-2026-102301 | High | GPU | Out-of-bounds write | |
| CVE-2026-102319 | High | GPU | Uninitialized resource | |
| CVE-2026-102324 | High | Picture-in-Picture | Use-after-free | Blockian Creator of Kritt and Open-Kritt |
| CVE-2026-102318 | High | WebGL | Out-of-bounds read | |
| CVE-2026-102329 | High | WebUI | Cross-site scripting | chipsec |
| CVE-2026-102315 | High | Media | Uninitialized resource | |
| CVE-2026-102302 | High | V8 | Buffer overflow | |
| CVE-2026-102321 | High | V8 | Type confusion | Taisic Yun, Theori, with Xint |
| CVE-2026-102320 | Medium | CORS | Missing authorization | Anonymous |
| CVE-2026-102310 | Low | Payments | Missing authorization | Autodidact |
| CVE-2026-102327 | Low | WebView | Incorrect authorization | |
| CVE-2026-102330 | Low | Site Isolation | Incorrect authorization | |
| CVE-2026-102314 | Low | TabStrip | UI misrepresentation | |
| CVE-2026-102305 | Low | SignIn | UI misrepresentation |
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/google-chrome-154-update/