Google has released Chrome 154 to the Stable desktop channel, addressing 32 security vulnerabilities, including a critical buffer overflow flaw in the ANGLE graphics translation layer. The update is rolling out as version 154.0.8037.92/.93 for Windows and macOS, and 154.0.8037.92 for Linux.
The most severe issue, tracked as CVE-2026-102331, is a critical buffer overflow in ANGLE, the component Chrome uses to translate graphics API calls for cross-platform rendering.
Memory-safety flaws of this type can be particularly serious because they may allow an attacker to corrupt memory when a user processes malicious web content.
Google Chrome 154 Update Fixes 32 Security Flaws
The release also remediates 25 high-severity issues across Chrome’s V8 JavaScript engine, GPU stack, WebGPU, WebGL, Mojo IPC framework, Bluetooth implementation, Views user-interface framework, Passwords, FullScreen, Picture-in-Picture, WebUI, Skia, Media, and Omnibox.
Several of the high-severity defects are type-confusion vulnerabilities in V8, while others involve use-after-free, uninitialized-resource, out-of-bounds read/write, cross-site scripting, and privilege-management weaknesses.
Notably, three high-severity V8 type-confusion vulnerabilities, CVE-2026-102323, CVE-2026-102326, and CVE-2026-102328, were reported by OpenAI Codex Security researcher amyb.
The company may also retain restrictions for bugs affecting third-party libraries until other dependent projects have deployed patches. No vulnerabilities in the advisory were marked as known to be exploited in the wild.
Chrome users should update immediately by going to Settings > About Chrome, letting the browser download the latest release, and relaunching it to complete installation.
Enterprise administrators should prioritize rollout because the patch set includes browser-engine, graphics-processing, sandbox-adjacent, and user-interface vulnerabilities that attackers could reach through controlled websites.
| CVE | Severity | Component | Vulnerability type |
|---|---|---|---|
| CVE-2026-102331 | Critical | ANGLE | Buffer overflow |
| CVE-2026-102317 | High | Mojo | Improper privilege management |
| CVE-2026-102312 | High | Omnibox | UI misrepresentation |
| CVE-2026-102313 | High | ANGLE | Uninitialized resource |
| CVE-2026-102299 | High | V8 | Type confusion |
| CVE-2026-102306 | High | Bluetooth | Use-after-free |
| CVE-2026-102307 | High | Dawn | Uninitialized resource |
| CVE-2026-102323 | High | V8 | Type confusion |
| CVE-2026-102303 | High | GPU | Uninitialized resource |
| CVE-2026-102311 | High | GPU | Uninitialized resource |
| CVE-2026-102300 | High | WebGPU | Uninitialized resource |
| CVE-2026-102326 | High | V8 | Type confusion |
| CVE-2026-102316 | High | Views | Use-after-free |
| CVE-2026-102304 | High | Passwords | Use-after-free |
| CVE-2026-102328 | High | V8 | Type confusion |
| CVE-2026-102309 | High | FullScreen | Use-after-free |
| CVE-2026-102325 | High | Skia | Uninitialized resource |
| CVE-2026-102308 | High | Views | Use-after-free |
| CVE-2026-102301 | High | GPU | Out-of-bounds write |
| CVE-2026-102319 | High | GPU | Uninitialized resource |
| CVE-2026-102324 | High | Picture-in-Picture | Use-after-free |
| CVE-2026-102318 | High | WebGL | Out-of-bounds read |
| CVE-2026-102329 | High | WebUI | Cross-site scripting |
| CVE-2026-102315 | High | Media | Uninitialized resource |
| CVE-2026-102302 | High | V8 | Buffer overflow |
| CVE-2026-102321 | High | V8 | Type confusion |
| CVE-2026-102320 | Medium | CORS | Missing authorization |
| CVE-2026-102310 | Low | Payments | Missing authorization |
| CVE-2026-102327 | Low | WebView | Incorrect authorization |
| CVE-2026-102330 | Low | Site Isolation | Incorrect authorization |
| CVE-2026-102314 | Low | TabStrip | UI misrepresentation |
| CVE-2026-102305 | Low | SignIn | UI misrepresentation |
Google noted that its security testing pipeline uses technologies including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL to identify flaws before release.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team