Google Chrome Browser (154.0.8037.57) Security Update Recommendation

Google Chrome Browser (154.0.8037.57) Security Update Recommendation
  • Google has released a security update that addresses vulnerabilities in the Chrome browser.
  • Affected systems include Windows and Mac systems running Chrome versions earlier than 154.0.8037.57/.58, And Linux systems running versions earlier than 154.0.8037.57.
  • This update addresses a total of 108 security vulnerabilities, including 11 critical, 25 high, 47 moderate, and 25 low-severity vulnerabilities.
  • Key vulnerabilities include a use-after-free vulnerability in AdFilter (CVE-2026-95310), buffer overflow vulnerabilities in ANGLE (CVE-2026-95281, CVE-2026-95284, CVE-2026-95350), a memory free-and-use vulnerability in Fullscreen (CVE-2026-95313), an out-of-bounds write vulnerability in GPU (CVE-2026-95322, CVE-2026-95357), a memory deallocation and reuse vulnerability in ServiceWorker (CVE-2026-95339), and buffer overflow and out-of-bounds write vulnerabilities in WebGL (CVE-2026-95349, CVE-2026-95329), and a memory deallocation and reuse vulnerability in WindowDialog (CVE-2026-95356).
  • High-severity vulnerabilities include memory deallocation and reuse, type confusion, missing permissions, and other issues in various features such as Aura, Bindings, Bluetooth, Browser, Chromecast, DevTools, Extensions, GPU, HID, IndexedDB, Navigation, PDFium, Platform, SecurityIndicators, Tint, V8, Video, Views, WebAudio, and others, including memory deallocation and reuse, type confusion, lack of authorization, buffer overflow, race conditions, and user interface display errors.
  • Medium-severity vulnerabilities include memory deallocation and reuse, type confusion, missing permissions, buffer overflows, race conditions, and user interface display errors found in Actor, Auth, BrowserTag, Chromium, Chromoting, Contextual Tasks, Core, Desktop, Downloads, Editing, FileSystem, Fonts, MediaCapture, MediaStream, Messages, Metrics, Mobile, Network, NFC, Passwords, Payments, Printing, Scroll, SmartCard, Themes, Transactions Platform, Updater, Verifier, WebAPKs, and XML, including memory reuse after deallocation, missing permissions, incorrect permissions, information disclosure, race conditions, insufficient input validation, user interface display errors, and insufficient security validation.
  • Low-severity vulnerabilities include those arising from Bluetooth, Chromoting, Core, DataTransfer, DevTools, ExtensionsMenu, Metrics, Mobile, Networking, Omnibox, Performance, Picture-in-Picture, PlatformIntegration, Printing, Safe Browsing, V8, WakeLock, WebProtect, and WebView, among others, and include vulnerabilities related to incomplete cleanup, information disclosure, integer overflow, missing permissions, user interface display errors, insufficient security validation, and incorrect reference resolution.
  • Google provided Vulnerability Patches for these vulnerabilities in an update released on September 22, 2026; users of these versions should update to the latest version.