TL;DR
Google pushed Chrome 154.0.8037.97/.98 to the Stable channel with 11 security fixes. The headline bug, CVE-2026-103628, is a critical WebGL flaw that can lead to code execution outside the sandbox. This Chrome security update rolls out over the coming days and weeks.
- Total: 11 CVEs
- Severity: 1 Critical · 2 High · 8 Unrated
- Actively exploited: None confirmed
- Highest severity: 9.6 (Critical · CVSSv3) — CVE-2026-103628
- Action: Apply the latest security updates now
Running Infra, AppSec, and SOC teams? Tag Google alerts by team automatically.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-103628 | 9.6 | CWE-787 | 154.0.8037.97 | Not exploited |
| CVE-2026-103625 | 8.8 | CWE-843 | 154.0.8037.97 | Not exploited |
| CVE-2026-103622 | 8.8 | CWE-416 | 154.0.8037.97 | Not exploited |
| CVE-2026-103626 | Awaiting analysis | CWE-863 | 154.0.8037.97 | Not exploited |
| CVE-2026-103621 | Awaiting analysis | CWE-190 | 154.0.8037.97 | Not exploited |
| CVE-2026-103630 | Awaiting analysis | CWE-416 | 154.0.8037.97 | Not exploited |
| CVE-2026-103624 | Awaiting analysis | CWE-416 | 154.0.8037.97 | Not exploited |
| CVE-2026-103629 | Awaiting analysis | CWE-190 | 154.0.8037.97 | Not exploited |
Why It Matters
The CVE record for CVE-2026-103628 says a remote attacker could “execute arbitrary code outside the sandbox via a crafted HTML page.” In other words, a single malicious site could break past Chrome’s main defense layer.
Google has not flagged any of these bugs as exploited in the wild. Similarly, no public proof-of-concept has been confirmed, and none appear in CISA’s KEV catalog.
How the Attacks Work
Critical WebGL Bug
CVE-2026-103628 is an out-of-bounds write in WebGL, the browser’s 3D graphics engine. Google’s own team found it on August 21. A victim only needs to load a crafted web page. The bad write then corrupts memory, which can hand an attacker code execution. Because the code runs outside the sandbox, the attacker does not need a second bug to escape it.
High-Severity Memory Flaws
Nine high-severity bugs follow. Four are use-after-free flaws in FedCM, Contextual Tasks, SVG, and MediaStream. Others include a V8 type confusion, integer overflows in Compositing and Skia, and a FileSystem authorization bug.
Notably, CVE-2026-103631 is a WebRTC buffer overflow. Xinyang Ge of Anthropic reported it, “assisted by Claude.” A medium SVG information leak rounds out the list. Overall, Google found six of the 11 bugs, while outside researchers reported the rest.
Affected Versions
All Chrome desktop builds before 154.0.8037.97 are affected on Windows, Mac, and Linux.
Patch and Mitigation Steps
Install this Chrome security update now. Open Settings, then About Chrome, and let the browser download the new build. After that, restart Chrome to apply it. Full release notes appear in Google’s Stable Channel Update for Desktop post. Google may keep bug details private until most users have updated.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!