« All news

AlertCritical· Updated on

Google fixes 95 vulnerabilities in Chrome, 23 of them critical, in its latest Stable channel update

Google has released a Stable channel update for Chrome on desktop that fixes 95 vulnerabilities. Twenty-three of them carry a CVSS score of 9.6 and could allow code execution outside the browser sandbox simply by visiting a malicious page. Chromium-based browsers such as Microsoft Edge are also affected.

What happened

On 29 September 2026 Google published a Stable channel update for Chrome on desktop that fixes a total of 95 vulnerabilities. The Chrome Releases advisory itself does not spell out the version numbers, but data from NVD and Microsoft's MSRC advisories place the fix in version 154.0.8037.57 for most of the flaws and in 154.0.8037.92 for a specific group, so the advice is to move to the latest available build.

The attack pattern is the usual one for browsers: a crafted HTML page that the victim opens, in some cases with the help of social engineering. The most serious flaws break out of the browser sandbox and run code on the machine; the rest are confined to the sandbox, leak information or bypass permission checks.

Some of these vulnerabilities are currently documented only in Microsoft's advisories for Chromium-based Edge; NVD has not published them yet.

The 23 critical vulnerabilities

Twenty-three flaws share a CVSS score of 9.6 because they allow arbitrary code execution outside the sandbox. They break down as follows:

The rest of the batch

The remaining 72 vulnerabilities range from high to low severity, and some have no score assigned yet. Grouped by flaw type and component:

Who is affected and exploitation status

Any Google Chrome installation older than the fixed versions is affected, on desktop and also on Android, iOS, macOS and Windows, depending on what each flaw description states. Because the code base is shared, Chromium-based browsers are equally exposed: Microsoft has issued its own advisories for Edge covering many of these CVEs.

None of the 95 vulnerabilities appears in CISA's KEV catalogue, so there is no confirmed active exploitation. None has an EPSS score yet either, so there is no published estimate of short-term exploitation likelihood. That does not make patching less urgent: browser flaws are routinely weaponised shortly after technical details become public.

What to do

The fix is straightforward and no additional mitigation is required: just update. We recommend the following steps:

Sources

Affected technologies

Google ChromeGoogle Chrome for AndroidGoogle Chrome for iOSChromiumMicrosoft Edge

Vulnerabilities (95)

CVESeverityActive exploitationPublishedNVD status
CVE-2026-102304Critical (9.6)—9/29/2026Analyzed
CVE-2026-102306Critical (9.6)—9/29/2026Analyzed
CVE-2026-102308Critical (9.6)—9/29/2026Analyzed
CVE-2026-102309Critical (9.6)—9/29/2026Analyzed
CVE-2026-102316Critical (9.6)—9/29/2026Analyzed
CVE-2026-102331Critical (9.6)—9/29/2026Analyzed
CVE-2026-102299High (8.8)—9/29/2026Undergoing Analysis
CVE-2026-102302High (8.8)—9/29/2026Undergoing Analysis
CVE-2026-102321High (8.8)—9/29/2026Analyzed
CVE-2026-102323High (8.8)—9/29/2026Analyzed
CVE-2026-102326High (8.8)—9/29/2026Analyzed
CVE-2026-102328High (8.8)—9/29/2026Analyzed
CVE-2026-95313Critical (9.6)—9/29/2026Analyzed
CVE-2026-95329Critical (9.6)—9/29/2026Analyzed
CVE-2026-95339Critical (9.6)—9/29/2026Analyzed
CVE-2026-95349Critical (9.6)—9/29/2026Analyzed
CVE-2026-95350Critical (9.6)—9/29/2026Analyzed
CVE-2026-95356Critical (9.6)—9/29/2026Analyzed
CVE-2026-95357Critical (9.6)—9/29/2026Analyzed
CVE-2026-95280High (7.5)—9/29/2026Analyzed
CVE-2026-95282High (8.8)—9/29/2026Analyzed
CVE-2026-95286High (8.8)—9/29/2026Analyzed
CVE-2026-95304High (8.8)—9/29/2026Analyzed
CVE-2026-95306High (8.8)—9/29/2026Analyzed
CVE-2026-95343High (8.8)—9/29/2026Analyzed
CVE-2026-95345High (8.8)—9/29/2026Analyzed
CVE-2026-95353High (8.8)—9/29/2026Analyzed
CVE-2026-95365High (8.8)—9/29/2026Undergoing Analysis
CVE-2026-95369High (8.8)—9/29/2026Undergoing Analysis
CVE-2026-95373High (8.8)—9/29/2026Undergoing Analysis
CVE-2026-95380High (8.8)—9/29/2026Undergoing Analysis
CVE-2026-95274High (8.3)—9/29/2026Analyzed
CVE-2026-95276High (8.3)—9/29/2026Analyzed
CVE-2026-95319High (8.3)—9/29/2026Analyzed
CVE-2026-95322High (8.3)—9/29/2026Analyzed
CVE-2026-95334High (8.3)—9/29/2026Analyzed
CVE-2026-95335High (8.3)—9/29/2026Analyzed
CVE-2026-95341High (8.3)—9/29/2026Analyzed
CVE-2026-95348High (8.3)—9/29/2026Analyzed
CVE-2026-95351High (8.3)—9/29/2026Analyzed
CVE-2026-95354High (8.3)—9/29/2026Analyzed
CVE-2026-95355High (8.3)—9/29/2026Analyzed
CVE-2026-95372High (8.3)—9/29/2026Undergoing Analysis
CVE-2026-95381High (8.3)—9/29/2026Undergoing Analysis
CVE-2026-95275Unscored—9/29/2026Undergoing Analysis
CVE-2026-95277Critical (9.6)—9/29/2026Analyzed
CVE-2026-95278Unscored—9/29/2026Undergoing Analysis
CVE-2026-95281Critical (9.6)—9/29/2026Analyzed
CVE-2026-95283Critical (9.6)—9/29/2026Analyzed
CVE-2026-95284Unscored—9/29/2026Undergoing Analysis
CVE-2026-95285Unscored—9/29/2026Undergoing Analysis
CVE-2026-95287Medium (5.4)—9/29/2026Analyzed
CVE-2026-95289Medium (4.3)—9/29/2026Analyzed
CVE-2026-95290Medium (5.4)—9/29/2026Undergoing Analysis
CVE-2026-95292Medium (4.8)—9/29/2026Analyzed
CVE-2026-95293Medium (4.7)—9/29/2026Analyzed
CVE-2026-95295Medium (4.6)—9/29/2026Undergoing Analysis
CVE-2026-95296Medium (4.3)—9/29/2026Analyzed
CVE-2026-95297Medium (6.5)—9/29/2026Undergoing Analysis
CVE-2026-95298High (7.8)—9/29/2026Analyzed
CVE-2026-95299Critical (9.6)—9/29/2026Analyzed
CVE-2026-95300Medium (4.8)—9/29/2026Undergoing Analysis
CVE-2026-95310Critical (9.6)—9/29/2026Analyzed
CVE-2026-95311Critical (9.6)—9/29/2026Analyzed
CVE-2026-95318Critical (9.6)—9/29/2026Analyzed
CVE-2026-95325Critical (9.6)—9/29/2026Analyzed
CVE-2026-95331Critical (9.6)—9/29/2026Analyzed
CVE-2026-95347Critical (9.6)—9/29/2026Analyzed
CVE-2026-95338High (8.8)—9/29/2026Analyzed
CVE-2026-95333High (8.1)—9/29/2026Analyzed
CVE-2026-95315High (7.8)—9/29/2026Analyzed
CVE-2026-95301High (8.1)—9/29/2026Undergoing Analysis
CVE-2026-95303Unscored—9/29/2026Undergoing Analysis
CVE-2026-95308Low (3.4)—9/29/2026Analyzed
CVE-2026-95314Unscored—9/29/2026Undergoing Analysis
CVE-2026-95324Low (3.4)—9/29/2026Analyzed
CVE-2026-95326Unscored—9/29/2026Undergoing Analysis
CVE-2026-95327Medium (6.5)—9/29/2026Analyzed
CVE-2026-95330Medium (6.5)—9/29/2026Undergoing Analysis
CVE-2026-95332Medium (4.7)—9/29/2026Analyzed
CVE-2026-95340Medium (4.3)—9/29/2026Undergoing Analysis
CVE-2026-95342Medium (4.3)—9/29/2026Undergoing Analysis
CVE-2026-95344High (8)—9/29/2026Undergoing Analysis
CVE-2026-95352Medium (5.4)—9/29/2026Analyzed
CVE-2026-95358Medium (4.4)—9/29/2026Undergoing Analysis
CVE-2026-95359Low (3.4)—9/29/2026Analyzed
CVE-2026-95361Medium (4.3)—9/29/2026Undergoing Analysis
CVE-2026-95362High (8.8)—9/29/2026Undergoing Analysis
CVE-2026-95366Medium (6.5)—9/29/2026Undergoing Analysis
CVE-2026-95370Medium (5.4)—9/29/2026Undergoing Analysis
CVE-2026-95374Unscored—9/29/2026Undergoing Analysis
CVE-2026-95375Medium (6.3)—9/29/2026Undergoing Analysis
CVE-2026-95376High (8)—9/29/2026Undergoing Analysis
CVE-2026-95384Medium (5.3)—9/29/2026Undergoing Analysis
CVE-2026-95385Unscored—9/29/2026Undergoing Analysis

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.