Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical
Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical
Google Chrome users have another major security update waiting, and this one closes more than 100 vulnerabilities at once.
Google released Chrome 154 to the stable channel on Sept. 22 with 108 security fixes, including 11 vulnerabilities rated Critical. The update is rolling out to Windows, macOS, and Linux users over the coming days and weeks.
While Google’s release notes do not mention any of the newly patched vulnerabilities as being actively exploited in the wild, several involve serious memory-safety problems in important Chrome components. That makes updating especially important for users and IT teams managing Chrome across business devices.
Chrome 154 patches 108 flaws, including 11 Critical vulnerabilities
According to Google’s release notes, Chrome 154.0.8037.57 is rolling out for Linux, while versions 154.0.8037.57/.58 are rolling out for Windows and macOS.
The release addresses 108 security issues in total. SecurityWeek reported that 11 are rated Critical, while another 25 are rated High severity.
The Critical vulnerabilities include:
- CVE-2026-95350: A buffer overflow in ANGLE, Chrome’s graphics translation layer.
- CVE-2026-95357: An out-of-bounds write vulnerability affecting the GPU component.
- CVE-2026-95339: A use-after-free vulnerability in ServiceWorker.
- CVE-2026-95281: Another buffer overflow affecting ANGLE.
- CVE-2026-95313: A use-after-free flaw affecting Chrome’s Fullscreen component.
Other Critical vulnerabilities affect WebGL, GPU, WindowDialog, and AdFilter. The group includes additional buffer overflows, out-of-bounds writes, and use-after-free vulnerabilities.
Google is temporarily restricting access to some vulnerability details until a larger percentage of Chrome users receive the fixes. The company may also keep information restricted when a vulnerability affects a third-party library used by other projects that have not yet patched the issue.
Google’s release notes do not mention any of the 108 vulnerabilities as being actively exploited in the wild.
Advertisement
Why Chrome keeps getting massive security updates
Chrome 154 is far from Google’s first unusually large security release this year.
In July, Chrome 151 patched 370 vulnerabilities, including seven Critical flaws. Earlier that month, another Chrome update fixed 382 security bugs across desktop and mobile.
The volume and frequency of Chrome security fixes are also putting more emphasis on faster browser patching. In August, TechRepublic reported that Google was testing twice-weekly Chrome security updates, potentially reducing the time users remain exposed to newly discovered vulnerabilities.
The browser has also faced more urgent security problems this year. In April, TechRepublic reported on a Chrome vulnerability under active attack, illustrating the potential consequences when browser vulnerabilities move from research findings to real-world exploitation.
How to check whether Chrome 154 is installed
Users do not necessarily have to wait for Chrome to prompt them about an update.
On desktop, open Chrome’s three-dot menu and select Help > About Google Chrome. Chrome will check for available updates on that page. If an update is ready, select Relaunch to restart the browser and apply it.
Desktop users should look for the following versions:
- Windows: Chrome 154.0.8037.57/.58
- macOS: Chrome 154.0.8037.57/.58
- Linux: Chrome 154.0.8037.57
The update is being rolled out gradually, so it may not appear immediately on every device.
Google also released Chrome 154.0.8037.57 for Android on Sept. 22, with the update becoming available through Google Play over the following days. Google said the Android release contains the same security fixes as the corresponding desktop release unless otherwise noted.
Advertisement
Must-read security coverage
What Chrome users and IT teams should do now
For individual Chrome users, the takeaway is straightforward: check for updates and relaunch the browser once they install. Users who routinely leave Chrome running for days at a time should pay particular attention to the relaunch step.
For IT administrators, Chrome 154 is another reason to verify browser versions across managed endpoints rather than assuming automatic updates have finished the job. Organizations should confirm that Windows, macOS, and Linux devices have reached the patched Chrome 154 builds and investigate systems that remain behind.
Google’s release notes do not indicate that any of the 108 vulnerabilities are being actively exploited, unlike some Chrome security updates this year that addressed known in-the-wild exploitation. But with 11 Critical vulnerabilities affecting components such as GPU, WebGL, ANGLE, and ServiceWorker, delaying the availability of a security update leaves browsers exposed to flaws for which fixes are already available.
Chrome’s recent run of large security updates is another reminder that browser patching should be treated as routine endpoint maintenance rather than an occasional task. For businesses that rely heavily on browser-based applications, keeping Chrome up to date should be treated alongside operating system and application patching as a regular part of endpoint security.
Read next: See how Google is testing twice-weekly Chrome updates to get security fixes onto users’ devices faster.
