Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Bug

Google has released Chrome 154 to the Stable desktop channel, addressing 32 security vulnerabilities, including a critical buffer overflow flaw in the ANGLE graphics translation layer. The update is rolling out as version 154.0.8037.92/.93 for Windows and macOS, and 154.0.8037.92 for Linux.

The most severe issue, tracked as CVE-2026-102331, is a critical buffer overflow in ANGLE, the component Chrome uses to translate graphics API calls for cross-platform rendering.

Memory-safety flaws of this type can be particularly serious because they may allow an attacker to corrupt memory when a user processes malicious web content.

Google Chrome 154 Update Fixes 32 Security Flaws

The release also remediates 25 high-severity issues across Chrome’s V8 JavaScript engine, GPU stack, WebGPU, WebGL, Mojo IPC framework, Bluetooth implementation, Views user-interface framework, Passwords, FullScreen, Picture-in-Picture, WebUI, Skia, Media, and Omnibox.

Several of the high-severity defects are type-confusion vulnerabilities in V8, while others involve use-after-free, uninitialized-resource, out-of-bounds read/write, cross-site scripting, and privilege-management weaknesses.

Notably, three high-severity V8 type-confusion vulnerabilities, CVE-2026-102323, CVE-2026-102326, and CVE-2026-102328, were reported by OpenAI Codex Security researcher amyb.

The company may also retain restrictions for bugs affecting third-party libraries until other dependent projects have deployed patches. No vulnerabilities in the advisory were marked as known to be exploited in the wild.

Chrome users should update immediately by going to Settings > About Chrome, letting the browser download the latest release, and relaunching it to complete installation.

Enterprise administrators should prioritize rollout because the patch set includes browser-engine, graphics-processing, sandbox-adjacent, and user-interface vulnerabilities that attackers could reach through controlled websites.

CVESeverityComponentVulnerability type
CVE-2026-102331CriticalANGLEBuffer overflow
CVE-2026-102317HighMojoImproper privilege management
CVE-2026-102312HighOmniboxUI misrepresentation
CVE-2026-102313HighANGLEUninitialized resource
CVE-2026-102299HighV8Type confusion
CVE-2026-102306HighBluetoothUse-after-free
CVE-2026-102307HighDawnUninitialized resource
CVE-2026-102323HighV8Type confusion
CVE-2026-102303HighGPUUninitialized resource
CVE-2026-102311HighGPUUninitialized resource
CVE-2026-102300HighWebGPUUninitialized resource
CVE-2026-102326HighV8Type confusion
CVE-2026-102316HighViewsUse-after-free
CVE-2026-102304HighPasswordsUse-after-free
CVE-2026-102328HighV8Type confusion
CVE-2026-102309HighFullScreenUse-after-free
CVE-2026-102325HighSkiaUninitialized resource
CVE-2026-102308HighViewsUse-after-free
CVE-2026-102301HighGPUOut-of-bounds write
CVE-2026-102319HighGPUUninitialized resource
CVE-2026-102324HighPicture-in-PictureUse-after-free
CVE-2026-102318HighWebGLOut-of-bounds read
CVE-2026-102329HighWebUICross-site scripting
CVE-2026-102315HighMediaUninitialized resource
CVE-2026-102302HighV8Buffer overflow
CVE-2026-102321HighV8Type confusion
CVE-2026-102320MediumCORSMissing authorization
CVE-2026-102310LowPaymentsMissing authorization
CVE-2026-102327LowWebViewIncorrect authorization
CVE-2026-102330LowSite IsolationIncorrect authorization
CVE-2026-102314LowTabStripUI misrepresentation
CVE-2026-102305LowSignInUI misrepresentation

Google noted that its security testing pipeline uses technologies including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL to identify flaws before release.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories