Google released Chrome 154 for Windows, macOS, and Linux, fixing 108 vulnerabilities, including 11 critical memory-safety defects that malicious web content could potentially exploit for crashes, information disclosure, or attacker-controlled code execution. The critical issues include buffer overflows, out-of-bounds writes, and use-after-free conditions in ANGLE, WebGL, GPU components, ServiceWorker, Fullscreen, WindowDialog, and AdFilter. Updated builds are rolling out as 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and macOS.
The release also addresses browser-boundary and data-exposure weaknesses affecting V8, WebGPU, CORS, credential previews, extensions, DevTools, WebView, WebNFC, DRM capture controls, Android WebAPKs, and the macOS updater. Notable fixes prevent cross-origin GPU shader and framebuffer-memory disclosure, a CORS preflight-cache bypass that could enable blind CSRF-style state changes, cross-domain username leakage from grouped credentials, extension isolated-world boundary breaches, DevTools privilege escalation, and a Qualcomm GPU-driver-triggered write crash. Organizations should expedite Chrome updates across managed endpoints and ensure separately deployed Google Updater components are current on macOS.

See real exploitation activity before you spend the cycle.
62 events from the most recent confirmed update back to the earliest known activity.
Google disclosed CVE-2026-95380 as a low-severity V8 type-confusion vulnerability affecting Chrome before 154.0.8037.57. A crafted HTML page and user interaction could allow code execution inside the Chrome sandbox; CISA reported no known exploitation or expected automation in its SSVC assessment.
Google's CVE record identified CVE-2026-95373 as a high-severity use-after-free vulnerability in Chrome DevTools affecting versions before 154.0.8037.57. A crafted HTML page and user interaction could enable arbitrary code execution inside the Chrome sandbox; CISA reported no known exploitation or automation.
Google submitted the CVE record for CVE-2026-95372, a high-severity use-after-free flaw in Chrome's Chromecast functionality affecting versions before 154.0.8037.57. Exploitation requires a prior renderer compromise and crafted HTML and could enable code execution outside Chrome's sandbox; CISA reported no observed exploitation or automation.
Google disclosed CVE-2026-95365, a high-severity type-confusion vulnerability in Chrome IndexedDB affecting versions before 154.0.8037.57. A crafted HTML page could allow remote code execution within the Chrome sandbox after user interaction; CISA reported no known exploitation or automation.
Google’s CVE record for CVE-2026-95369 identified an inappropriate implementation in Chrome’s XML functionality affecting versions before 154.0.8037.57. A crafted HTML page could allow remote code execution within the Chrome sandbox after user interaction; CISA’s SSVC record reported no known exploitation or automation.
CISA recorded an SSVC assessment for CVE-2026-95381, an improper-input-validation flaw in Chrome's Printing component before 154.0.8037.57. Exploitation requires a prior renderer compromise and crafted HTML to potentially execute code outside Chrome's sandbox; CISA reported no known exploitation or expected automation.
FreeBSD advisory bd24bc14-b9a9-11f1-bf98-a8a1599412c6 published security fixes for the chromium and ungoogled-chromium packages, covering 108 Chromium vulnerabilities. Tenable Nessus plugin 350826 detects FreeBSD hosts reporting package versions older than the tested secure version; no known exploits were reported.
Google began an Early Stable rollout of Chrome 155.0.8059.16 for Android to a small percentage of users, citing stability and performance improvements. Chrome 155 was also available through the Beta channel.
The Canadian Centre for Cyber Security published advisory AV26-955, covering Google Chrome Stable Channel for Desktop versions prior to 154.0.8037.57/.58 on Windows and macOS and 154.0.8037.57 on Linux. It advised users and administrators to review Google's advisory and apply the necessary updates.
Tenable's Nessus Unix plugin recorded CVE-2026-95309 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Debian Chromium identified in associated product CPE information. It assigned a critical CVSS v3 score of 9.8 for network-accessible exploitation requiring no privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95352 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with the Debian Chromium package listed in affected CPE information. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95304 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium included in the Debian package CPE data. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation without privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95298 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium included in affected product CPE data. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95291 as unpatched on Debian Linux 12.0, 13.0, and 14.0, including a Debian Chromium package CPE entry. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation without privileges or user interaction and reported no known exploits.
Tenable's Nessus plugin recorded CVE-2026-95284 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium included in associated CPE information. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction and reported no known exploits.
Tenable's Nessus plugin recorded CVE-2026-95301 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium referenced in associated package CPE data. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix plugin recorded CVE-2026-95373 as unpatched on Debian Linux 12.0, 13.0, and 14.0, including Debian Chromium in its package CPE context. It assigned a critical CVSS v3 score of 9.8 for network-accessible exploitation requiring no privileges or user interaction and reported no known public exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95331 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with a Debian Chromium package CPE listed. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation without privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95380 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium listed in associated CPE information. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95322 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium included in associated product CPE data. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95318 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium included in affected CPE information. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction and reported no known public exploits.
Tenable's Nessus plugin recorded CVE-2026-95329 as unpatched on Debian Linux 12.0, 13.0, and 14.0, referencing the Debian Chromium package. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation without privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95277 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium referenced in associated package CPE information. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95281 as unpatched on Debian Linux 12.0, 13.0, and 14.0, including a Debian Chromium package CPE. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95360 as unpatched on Debian Linux 12.0, 13.0, and 14.0, including a Debian Chromium package CPE entry. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation without privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95368 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium included in the listed CPE data. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction, and reported no known exploits.
Tenable recorded CVE-2026-95328 as unpatched on Debian Linux 12.0, 13.0, and 14.0, with Chromium included in affected product CPE data. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation without privileges or user interaction and reported no known exploits.
Tenable's Nessus plugin recorded CVE-2026-95288 as unpatched on Debian Linux 12.0, 13.0, and 14.0, including the Debian Chromium package. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation without privileges or user interaction and reported no known exploits.
Tenable's Nessus Unix-agent plugin recorded CVE-2026-95346 as unpatched on Debian Linux 12.0, 13.0, and 14.0. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation requiring no privileges or user interaction, and reported no known exploits.
Tenable's Nessus plugin recorded CVE-2026-95359 as unpatched on Debian Linux 12.0, 13.0, and 14.0, including Debian Chromium. It assigned a critical CVSS v3 score of 9.8 for network-reachable exploitation without privileges or user interaction and reported no known public exploits.
Google accepted and fixed the macOS updater issue by deferring DataPipeDrainer deletion to the execution sequence instead of destroying it inside the active client callback.
A report disclosed that Chrome's grouped or weakly affiliated password suggestions could send a credential username preview for a different domain to the renderer before user confirmation. The report demonstrated amazon.com displaying the username associated with a weakly affiliated amazon.de credential; password values remained masked.
NH DEV reported that Chrome's preflight cache used the raw request initiator instead of the tainted request's serialized origin, allowing a preflight approved for Origin: null to potentially authorize a later credentialed state-changing request.
Chrome launched password suggestions based on grouped affiliations, the feature later found to expose username previews for weakly affiliated cross-domain credentials.
Project Fortify reported that WebNFC permission handling could associate an opaque-origin document with its visible URL, potentially permitting a compromised renderer to reuse an existing WebNFC grant for a victim origin.
Qualcomm fixed the underlying Adreno graphics-driver flaw behind the Chrome Android mutable-3D-texture out-of-bounds write issue before July 21.
An anonymous reporter filed a Chrome Android issue showing that valid WebGL/OpenGL ES calls increasing a mutable 3D texture's depth could trigger a SIGSEGV write in the privileged GPU process through a Qualcomm Adreno driver.
A streamed-download change introduced a use-after-free condition in the macOS Google Updater fallback stream reader when destination-file write failures caused its active DataPipeDrainer to be destroyed during a callback.
The experimental Flapjack security project reported that DesktopCaptureAccessHandler failed to record the true captured surface, potentially allowing an extension with desktopCapture permission to record DRM-protected screen or window content.
A report identified that a sideloaded app spoofing the retired Maps Lite WebAPK package could potentially claim arbitrary origins and receive delegated web-push notification objects, including sensitive notification content.
Project Fortify reported that a compromised chrome-untrusted://lens renderer could use powerful WebView APIs to create spoofed HTTP(S)-origin content, bypass Private Network Access or CORS protections for local endpoints, and execute fresh-session script under arbitrary HTTPS origins.
Google released Chrome 154 for Windows, macOS, and Linux, addressing 108 vulnerabilities including critical memory-safety flaws in ANGLE, WebGL, GPU components, and browser features. The rollout versions were 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and macOS.
Google registered CVEs including CVE-2026-95275, CVE-2026-95290, CVE-2026-95300, CVE-2026-95302, CVE-2026-95312, CVE-2026-95332, CVE-2026-95342, CVE-2026-95347, CVE-2026-95353, CVE-2026-95357, CVE-2026-95359, CVE-2026-95374, and CVE-2026-95375, and set their vulnerability release-note targets to Chrome M154.
The Chrome Vulnerability Rewards Program panel concluded that the macOS Google Updater use-after-free report did not qualify for a reward because it found no clear exploitation path.
The Chrome Vulnerability Reward Program awarded the anonymous reporter $2,500 for the Qualcomm GPU vulnerability report.
V8 extended its security-token filtering to all 19 CallSitePrototype getters and WebAssembly frames, returning filtered values for incompatible realms.
Chromium committed checks preventing remotely loaded DevTools frontends from invoking privileged operations such as browser restart, Chrome-flag changes, file-system actions, port forwarding, and device updates.
Google marked the Qualcomm-driven Chrome Android GPU out-of-bounds write vulnerability fixed after driver remediation and Chrome/ANGLE mitigations were available.
V8 patched CallSite getFunction(), getThis(), and getFunctionName() to reject values from incompatible security-token contexts, preventing untrusted Error.prepareStackTrace handlers from obtaining trusted functions.
Chromium added a GPU workaround that loses the GL context when glTexImage3D increases the depth of a mutable 3D texture on affected Qualcomm configurations, mitigating the underlying Adreno driver out-of-bounds-write condition.
Chromium rolled the fixed ANGLE revision containing the mutable-3D-texture mitigation into chromium/src for the Qualcomm GPU issue.
Chromium added opaque-origin checks in NFCHost and NfcPermissionContext to deny WebNFC binding and permissions to sandboxed or otherwise opaque-origin documents.
Chromium removed the deprecated Maps Lite allowlist from WebApkValidator, preventing sideloaded apps from abusing the unauthenticated package-validation path for notification delegation.
V8 changed FastIterateArray to preserve iteration state in DirectHandle objects and handle scopes across callbacks that can trigger compacting garbage collection, addressing a potential stale-pointer use-after-free.
Chromium banned loadDataWithBaseUrl, executeScript, and other high-risk WebView APIs for chrome-untrusted pages, closing the Lens WebUI origin-spoofing and PNA-bypass path.
Chromium changed Region Capture APIs to keep separate ScriptPromiseResolvers for each caller ScriptState, preventing webpages from receiving Promises and objects created in an extension isolated world.
ANGLE merged a workaround that recreates mutable 3D textures and copies their existing levels when glTexImage3D increases texture depth, mitigating the Qualcomm driver issue.
Dawn changed the SPIR-V handling of subgroupBroadcast so an out-of-range subgroup ID returns an indeterminate value rather than potentially returning register data to JavaScript.
Chromium passed the resolved DesktopMediaID into capture setup and invoked UpdateTarget(), ensuring full-screen and window captures are correctly tracked for output-protection decisions.
Chromium added texture sample-count and layer fields to framebuffer-completeness cache signatures, preventing incomplete framebuffers from inheriting a cached complete status and potentially exposing uncleared GPU memory.
Chromium committed a fix using an opaque origin as the cache key for tainted requests, preventing tainted Origin: null preflight entries from being reused by untainted requests.
Chromium removed username previews for grouped credentials after determining that the suggested-password popup could send a cross-domain credential's full username to the renderer before user confirmation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecrbug.com
Open sourcecrbug.com
Open sourceissues.chromium.org
Open sourcecrbug.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.