11 critical gaps at a time. Google has released a big Chrome update

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
548
Reaction score
952
Deposit
0$
Google has released Chrome 154 with one of the largest security patches in recent years. The developers closed 108 vulnerabilities, and 11 of them received a critical level of danger. The update is already distributed to Windows, MacOS and Linux users.

Critical errors affect several important components of the browser. Three vulnerabilities were found in ANGLE, and two more allow you to record data outside the permissible GPU memory area. Problems were also found in WebGL, ServiceWorker, full-screen mode, WindowDialog and AdFilter. The AGNLE graphics layer has already become the source of critical Chrome vulnerabilities in previous releases.

The list includes CVE-2026-95350, CVE-2026-95357, CVE-2026-95339, CVE-2026-95281, CVE-2026-95313, CVE-2026-95349, CVE-2026-95349CVE-2026-9528CVE-2026-95322CVE-2026-95329CVE-2026-95356, CVE-2022, CVE-2022 Among the most common types of errors were buffer overflow, recording outside of allocated memory and accessing memory after its release.

Another 25 vulnerabilities received a high level of danger. The problems affected extensions, navigation, GPU, DevTools, Bluetooth, HID, PDFium, video processing, IndexedDB, WebAudio and other parts of the browser. Three serious errors were found in V8, including recording outside of memory and confusion of types. It was the V8 in September that was already the cause of an urgent update after the confirmed exploitation of another vulnerability in real attacks.


Two high-level bugs in V8, CVE-2026-95304 and CVE-2026-95306, the OpenAI Codex Security team discovered. The first is associated with recording outside the permissible memory area, the second with the confusion of types. Google has not yet disclosed details of some of the problems found, so that most users have time to switch to secure builds.

Chrome 154 received 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and macOS. Google listed the fixes on the September 22 bulletin and warned that the unfolding of the new version would take several days or weeks. In the publication, the company did not report the exploitation of the listed critical vulnerabilities in real attacks.

Large-scale fixes for Chrome in 2026 have already become familiar. In August, the Chrome 152 received 327 fixes, and the September Chrome 153 closed 230 security issues, including several critical WebGL bugs.

At the same time, the number of vulnerabilities that attackers manage to use before mass browser updates is growing. In early September, Google closed the sixth zero-day Chrome for 2026, and a few days later it was necessary to eliminate the seventh actively exploited problem.

Of particular importance is the restart of the browser after downloading the new version. Even the update installed in the background does not replace the running code before the Chrome restart, and browsers based on Chromium can receive appropriate fixes with delay. This gap between the appearance of a fix and its delivery to users creates a risk window that can be used by attackers.
 
Top Bottom