Overview:
-
108 Vulnerabilities Fixed: Chrome 154 resolves 11 Critical, 25 High, 47 Medium, and 25 Low-severity security issues.
-
Major Components Affected: Critical flaws impact ANGLE, GPU, WebGL, ServiceWorker, Fullscreen, WindowDialog, and AdFilter.
-
Updating is Important: While no known attacks currently target these defects, patched vulnerabilities can become easier to exploit following public disclosure.
Google has rolled out a significant security update for its web browser with the release of Chrome 154. The Stable Channel update addresses 108 security vulnerabilities, which include 11 classified as Critical and 25 as High. Released on September 22, 2026, Chrome 154 is reaching Windows, Mac, and Linux users through a gradual deployment phase spanning the next several days and weeks. The specific desktop version numbers are 154.0.8037.57 for Linux and versions 154.0.8037.57 and 154.0.8037.58 for Windows and Mac.
108 Security Flaws Get Fixes in Chrome 154
The total count of 108 resolved flaws spans a broad spectrum of security concerns, categorized into 11 Critical, 25 High, 47 Medium, and 25 Low severity issues. A large portion of the release focuses on memory safety bugs, impacting multiple browser components such as ANGLE, GPU, WebGL, ServiceWorker, Fullscreen, WindowDialog, and AdFilter.
Among the Critical entries, Google highlights several severe memory corruption vulnerabilities. CVE-2026-95350 involves a buffer overflow in ANGLE, whereas CVE-2026-95357 entails an out-of-bounds write within the GPU. Additionally, CVE-2026-95339 concerns a use-after-free weakness in ServiceWorker. Additional Critical bugs impact Fullscreen, WebGL, WindowDialog, and AdFilter. When malicious web content interacts with vulnerable components, these types of defects can introduce substantial security risks.
Critical Bugs Affect Core Chrome Components
ANGLE, the graphics backend utilized by Chrome, receives several Critical fixes in this latest version, including three Critical buffer overflow flaws identified by Google. The browser also addresses Critical out-of-bounds write defects in both the GPU and WebGL. Such vulnerabilities are particularly concerning because browsers rely heavily on graphics and other low-level modules to process complex web materials.
Furthermore, the update corrects use-after-free bugs located in ServiceWorker, Fullscreen, WindowDialog, and AdFilter. A use-after-free flaw allows software to access a memory region after it has been freed from the expected object’s control. Although public reports do not outline a confirmed attack path for every individual Chrome 154 flaw, adversaries can occasionally weaponize memory errors of this nature to trigger application crashes or execute more dangerous security exploits.
Also Read – How to Download Your Google Account Data
External Researchers Found 32 Flaws
Out of the 108 total vulnerabilities, Google identified 76 internally, while independent security researchers reported the remaining 32. External contributors discovered nine of the 11 Critical issues. At the time of publication, Google had disbursed $18,000 in bug bounty rewards, with final determinations for several additional reports still pending.
These payouts highlight the vital role external security research plays in reinforcing Chrome’s defenses. Independent analysts uncovered severe vulnerabilities spanning graphics modules, browser services, and other architectural layers. To mitigate premature exposure, Google intentionally restricts certain technical particulars until a majority of the user base has successfully obtained the patches, thereby limiting the actionable intelligence available to potential attackers.
No Known Exploits for These 108 Flaws
At the time of release, no reports indicated that the 108 vulnerabilities addressed in Chrome 154 were actively being exploited in the wild. Outlets such as SecurityWeek and PCWorld noted the absence of active attacks tied specifically to this patch batch. However, this status is subject to change once security analysts and threat actors examine the updated source code.
The absence of active attacks does not render older browser versions safe. Following the publication of a patch, researchers frequently compare the updated code against earlier releases to isolate the root cause of a defect. This reverse-engineering process can shed light on potential attack methodologies, making timely updates a critical precaution even before an exploit materializes in the wild.
Chrome 154 Also Reaches Android
On September 22, Google also introduced Chrome version 154.0.8037.57 for Android. According to Google, this mobile release incorporates the identical security corrections found in its desktop counterpart unless stated otherwise in the official release notes, with a phased Google Play rollout scheduled for the ensuing days.
Additionally, PCWorld documented the release of Chrome version 154.0.8037.55 for iOS. While version numbers may vary across operating systems, the Android edition integrates the core security improvements included in the desktop builds.
Also Read – Cybersecurity Risk Management Strategy & Checklist for 2026
How to Check for Chrome 154
Chrome typically checks for available updates automatically, but users can also initiate a manual check easily. Open the browser menu, navigate to Help, and select About Google Chrome. Alternatively, users can navigate directly to chrome://settings/help. Restarting the browser finalizes the installation once the newest version is downloaded.
Rather than introducing marquee user-facing features, Chrome 154 is noteworthy for the sheer volume and severity of its security remedies. Encompassing 108 vulnerabilities—including 11 Critical bugs, 25 High-severity issues, and numerous critical memory safety errors—this release provides a compelling incentive for users to upgrade to the latest stable edition promptly, regardless of the current absence of recorded attacks targeting these specific vulnerabilities.
FAQs
1. What does Chrome 154 fix?
Chrome 154 fixes 108 security vulnerabilities across multiple browser components.
2. How many Critical vulnerabilities were fixed?
The release addresses 11 Critical-severity vulnerabilities.
3. Are these Chrome 154 vulnerabilities being actively exploited?
There were no known real-world attacks targeting these specific vulnerabilities at the time of the release.
4. How can I update Chrome?
Go to Chrome → Help → About Google Chrome. Chrome will check for and install available updates.
5. Why should I update if there are no known attacks?
Publicly disclosed fixes can help researchers identify vulnerabilities and potentially develop exploits, making timely updates an important security measure.




