TL;DR
Google released a Chrome security update, version 154.0.8037.92/.93, that fixes 33 security flaws. The top issue is CVE-2026-102331, a critical buffer overflow in the ANGLE graphics layer. Google has not reported any of these flaws as exploited in the wild.
- Total: 32 CVEs
- Severity: 1 Critical · 6 High · 25 Unrated
- Actively exploited: None confirmed
- Highest severity: 9.6 (Critical · CVSSv3) — CVE-2026-102331
- Action: Apply the latest security updates now
Track every Google CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-102331 | 9.6 | 154.0.8037.92 | Not exploited |
| CVE-2026-102328 | 8.8 | 154.0.8037.92 | Not exploited |
| CVE-2026-102302 | 8.8 | 154.0.8037.92 | Not exploited |
| CVE-2026-102321 | 8.8 | 154.0.8037.92 | Not exploited |
| CVE-2026-102301 | 8.3 | 154.0.8037.92 | Not exploited |
| CVE-2026-102324 | 8.3 | 154.0.8037.92 | Not exploited |
| CVE-2026-102327 | 7.5 | 154.0.8037.92 | Not exploited |
| CVE-2026-102317 | Awaiting analysis | 154.0.8037.92 | Not exploited |
Why This Chrome Security Update Matters
This release lands only weeks after Chrome 154 shipped with 108 security fixes. The new batch is heavy on memory safety. It includes one Critical flaw, 25 High, one Medium, and five Low, based on the 32 CVEs Google listed publicly.
How the Attacks Work
Critical ANGLE Buffer Overflow
ANGLE translates web graphics calls into the system’s native graphics interface. A buffer overflow there, tracked as CVE-2026-102331, can corrupt memory while Chrome renders crafted content. A researcher known as @mfx reported it on August 24.
Six V8 Engine Bugs
Six High-severity fixes target V8, Chrome’s JavaScript engine. Five are type confusion bugs and one is a buffer overflow. OpenAI Codex Security reported three of the type confusion flaws.
GPU, Use-After-Free, and UI Flaws
Other High fixes cover uninitialized memory in GPU, WebGPU, Dawn, and Skia code. Several use-after-free bugs hit Views, Passwords, Bluetooth, and Picture-in-Picture. An Omnibox bug could also let a page misrepresent the address bar.
Affected Versions and Exploitation Status
All desktop Chrome builds before 154.0.8037.92 are affected. Google notes that “access to bug details and links may be kept restricted until a majority of users are updated with a fix.” No exploitation in the wild or public proof-of-concept has been reported.
Patch and Mitigation Steps
Update to 154.0.8037.92/.93 on Windows and Mac, or 154.0.8037.92 on Linux. Open Chrome settings, choose About Chrome, and relaunch after the download. The full list is in the Chrome Stable channel release notes. Because the rollout takes days or weeks, apply this Chrome security update manually rather than waiting.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!