Google fixes 95 vulnerabilities in Chrome, 23 of them critical, in its latest Stable channel update
Google has released a Stable channel update for Chrome on desktop that fixes 95 vulnerabilities. Twenty-three of them carry a CVSS score of 9.6 and could allow code execution outside the browser sandbox simply by visiting a malicious page. Chromium-based browsers such as Microsoft Edge are also affected.
What happened
On 29 September 2026 Google published a Stable channel update for Chrome on desktop that fixes a total of 95 vulnerabilities. The Chrome Releases advisory itself does not spell out the version numbers, but data from NVD and Microsoft's MSRC advisories place the fix in version 154.0.8037.57 for most of the flaws and in 154.0.8037.92 for a specific group, so the advice is to move to the latest available build.
The attack pattern is the usual one for browsers: a crafted HTML page that the victim opens, in some cases with the help of social engineering. The most serious flaws break out of the browser sandbox and run code on the machine; the rest are confined to the sandbox, leak information or bypass permission checks.
Some of these vulnerabilities are currently documented only in Microsoft's advisories for Chromium-based Edge; NVD has not published them yet.
The 23 critical vulnerabilities
Twenty-three flaws share a CVSS score of 9.6 because they allow arbitrary code execution outside the sandbox. They break down as follows:
- Graphics engine and GPU (ANGLE, WebGL, Tint, GPU): CVE-2026-102331, CVE-2026-95281, CVE-2026-95350, CVE-2026-95325, CVE-2026-95331, CVE-2026-95329, CVE-2026-95349, CVE-2026-95283, CVE-2026-95299 and CVE-2026-95357, several of them specific to Chrome on Android.
- Interface, windows and fonts (Views, WindowDialog, FullScreen, Fonts): CVE-2026-102308, CVE-2026-102316, CVE-2026-95277, CVE-2026-95356, CVE-2026-102309, CVE-2026-95313 and CVE-2026-95311.
- Other components: password manager (CVE-2026-102304), Bluetooth (CVE-2026-102306), ServiceWorker (CVE-2026-95339), ad filter (CVE-2026-95310), video (CVE-2026-95318) and the macOS updater (CVE-2026-95347), the latter exploitable through crafted network traffic.
The rest of the batch
The remaining 72 vulnerabilities range from high to low severity, and some have no score assigned yet. Grouped by flaw type and component:
- V8 JavaScript engine (type confusion, out-of-bounds write and race conditions), with code execution inside the sandbox: CVE-2026-102299, CVE-2026-102302, CVE-2026-102321, CVE-2026-102323, CVE-2026-102326, CVE-2026-102328, CVE-2026-95304, CVE-2026-95306, CVE-2026-95380, CVE-2026-95280 and CVE-2026-95342.
- Use-after-free and type confusion in browser components: CVE-2026-95343, CVE-2026-95345, CVE-2026-95353, CVE-2026-95286, CVE-2026-95338, CVE-2026-95373, CVE-2026-95319, CVE-2026-95335, CVE-2026-95348, CVE-2026-95351, CVE-2026-95354, CVE-2026-95372, CVE-2026-95333, CVE-2026-95298, CVE-2026-95315, CVE-2026-95282, CVE-2026-95365 and CVE-2026-95366.
- Input validation, output encoding and inappropriate implementations: CVE-2026-95274, CVE-2026-95276, CVE-2026-95341, CVE-2026-95381, CVE-2026-95369, CVE-2026-95322, CVE-2026-95334, CVE-2026-95355, CVE-2026-95284, CVE-2026-95370, CVE-2026-95385 and CVE-2026-95330.
- Information leaks and lower-impact issues: CVE-2026-95327, CVE-2026-95384, CVE-2026-95293, CVE-2026-95332, CVE-2026-95295, CVE-2026-95289, CVE-2026-95296, CVE-2026-95308, CVE-2026-95324 and CVE-2026-95359.
- Authorization and permission errors, still unscored in NVD: CVE-2026-95275, CVE-2026-95278, CVE-2026-95285, CVE-2026-95287, CVE-2026-95290, CVE-2026-95292, CVE-2026-95297, CVE-2026-95300, CVE-2026-95301, CVE-2026-95303, CVE-2026-95314, CVE-2026-95326, CVE-2026-95340, CVE-2026-95344, CVE-2026-95352, CVE-2026-95358, CVE-2026-95361, CVE-2026-95362, CVE-2026-95374, CVE-2026-95375 and CVE-2026-95376.
Who is affected and exploitation status
Any Google Chrome installation older than the fixed versions is affected, on desktop and also on Android, iOS, macOS and Windows, depending on what each flaw description states. Because the code base is shared, Chromium-based browsers are equally exposed: Microsoft has issued its own advisories for Edge covering many of these CVEs.
None of the 95 vulnerabilities appears in CISA's KEV catalogue, so there is no confirmed active exploitation. None has an EPSS score yet either, so there is no published estimate of short-term exploitation likelihood. That does not make patching less urgent: browser flaws are routinely weaponised shortly after technical details become public.
What to do
The fix is straightforward and no additional mitigation is required: just update. We recommend the following steps:
- Update Chrome to the latest Stable channel build (154.0.8037.92 or later) on all devices, including Android and iOS handsets. Chrome updates itself, but the fix only takes effect once the user restarts the browser.
- Push the update from your admin console or endpoint management tool and check the percentage of updated devices over the next 48 hours.
- Also update Microsoft Edge and any other Chromium-based browser, as well as desktop applications that embed Chromium.
- Pay particular attention to devices used by privileged users and to those handling credentials, since one of the critical flaws affects the password manager.
- Remind staff that exploitation requires opening a malicious page: reinforce the usual guidance on unsolicited links while the rollout is completed.
Sources
Affected technologies
Vulnerabilities (95)
| CVE | Severity | Active exploitation | Published | NVD status |
|---|---|---|---|---|
| CVE-2026-102304 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-102306 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-102308 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-102309 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-102316 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-102331 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-102299 | High (8.8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-102302 | High (8.8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-102321 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-102323 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-102326 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-102328 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95313 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95329 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95339 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95349 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95350 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95356 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95357 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95280 | High (7.5) | — | 9/29/2026 | Analyzed |
| CVE-2026-95282 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95286 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95304 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95306 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95343 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95345 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95353 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95365 | High (8.8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95369 | High (8.8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95373 | High (8.8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95380 | High (8.8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95274 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95276 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95319 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95322 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95334 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95335 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95341 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95348 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95351 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95354 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95355 | High (8.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95372 | High (8.3) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95381 | High (8.3) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95275 | Unscored | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95277 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95278 | Unscored | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95281 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95283 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95284 | Unscored | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95285 | Unscored | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95287 | Medium (5.4) | — | 9/29/2026 | Analyzed |
| CVE-2026-95289 | Medium (4.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95290 | Medium (5.4) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95292 | Medium (4.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95293 | Medium (4.7) | — | 9/29/2026 | Analyzed |
| CVE-2026-95295 | Medium (4.6) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95296 | Medium (4.3) | — | 9/29/2026 | Analyzed |
| CVE-2026-95297 | Medium (6.5) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95298 | High (7.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95299 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95300 | Medium (4.8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95310 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95311 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95318 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95325 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95331 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95347 | Critical (9.6) | — | 9/29/2026 | Analyzed |
| CVE-2026-95338 | High (8.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95333 | High (8.1) | — | 9/29/2026 | Analyzed |
| CVE-2026-95315 | High (7.8) | — | 9/29/2026 | Analyzed |
| CVE-2026-95301 | High (8.1) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95303 | Unscored | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95308 | Low (3.4) | — | 9/29/2026 | Analyzed |
| CVE-2026-95314 | Unscored | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95324 | Low (3.4) | — | 9/29/2026 | Analyzed |
| CVE-2026-95326 | Unscored | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95327 | Medium (6.5) | — | 9/29/2026 | Analyzed |
| CVE-2026-95330 | Medium (6.5) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95332 | Medium (4.7) | — | 9/29/2026 | Analyzed |
| CVE-2026-95340 | Medium (4.3) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95342 | Medium (4.3) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95344 | High (8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95352 | Medium (5.4) | — | 9/29/2026 | Analyzed |
| CVE-2026-95358 | Medium (4.4) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95359 | Low (3.4) | — | 9/29/2026 | Analyzed |
| CVE-2026-95361 | Medium (4.3) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95362 | High (8.8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95366 | Medium (6.5) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95370 | Medium (5.4) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95374 | Unscored | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95375 | Medium (6.3) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95376 | High (8) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95384 | Medium (5.3) | — | 9/29/2026 | Undergoing Analysis |
| CVE-2026-95385 | Unscored | — | 9/29/2026 | Undergoing Analysis |
Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.