Google released Chrome Stable 154.0.8037.92/.93 for Windows and macOS and 154.0.8037.92 for Linux, remediating 32 security vulnerabilities. The most severe issue, CVE-2026-102331, is a critical buffer overflow in ANGLE that can corrupt memory and potentially enable code execution in Chrome’s browser context.
The update also fixes 26 high-severity issues, including V8 type-confusion and buffer-overflow flaws potentially reachable through malicious webpages, along with use-after-free, out-of-bounds, and uninitialized-resource bugs. Affected components include GPU, WebGPU, Mojo, Bluetooth, Passwords, WebUI, CORS, Payments, WebView, and SiteIsolation. Google is restricting some technical details until adoption increases; it reported no active exploitation and advised users to update and relaunch Chrome promptly.

See affected versions and whether adversaries are exploiting it.
100 events from the most recent confirmed update back to the earliest known activity.
Fedora published the Chromium patch associated with advisory FEDORA-2026-53c8aca50a, updating Fedora 45's package to version 154.0.8037.97 to fix CVE-2026-103621 through CVE-2026-103631. Tenable classifies the update as critical, recommends updating the affected package, and reports no known available exploits.
Tenable published plugin 473348 identifying Chainguard Chromium packages affected by CVE-2026-102307, a Chrome Android Dawn uninitialized-resource flaw allowing memory reads outside the sandbox through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473280 identifying Chainguard chromium-lang packages affected by CVE-2026-102327, a Chrome Android WebView incorrect-authorization flaw that could allow arbitrary code execution outside the sandbox after renderer compromise. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473324 identifying Chainguard Chromium packages affected by CVE-2026-95285, a Chrome Android WebView missing-authorization flaw allowing web origin policy bypass through crafted HTML after renderer compromise. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473275 identifying Chainguard chromium-lang packages affected by CVE-2026-95317, a Chrome MediaCapture incorrect-authorization flaw allowing cross-origin data disclosure through social engineering and a crafted Chrome extension. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473304 identifying Chainguard Chromium packages affected by CVE-2026-95291, a Chrome iOS SecurityIndicators UI misrepresentation flaw allowing address-bar spoofing through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473318 identifying Chainguard Chromium packages affected by CVE-2026-95345, a Chrome Actor use-after-free flaw allowing arbitrary code execution inside the sandbox through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports available exploits, but not active exploitation.
Tenable published plugin 473313 identifying Chainguard Chromium packages affected by CVE-2026-95347, a Chrome Updater use-after-free flaw affecting Chrome on Mac that allows arbitrary code execution outside the sandbox through crafted network traffic. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473320 identifying Chainguard chromium-lang packages affected by CVE-2026-102304, a Chrome Passwords use-after-free flaw allowing arbitrary code execution outside the sandbox through crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473281 identifying Chainguard chromium-docker-selenium-compat packages affected by CVE-2026-102329, a Chrome WebUI cross-site scripting flaw allowing web origin policy bypass into a privileged page through crafted HTML. It recommends updating the package and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473268 identifying Chainguard chromium-docker-selenium-compat packages affected by CVE-2026-95292, a Chrome Safe Browsing incorrect-authorization flaw allowing system access restrictions to be bypassed through crafted network traffic. It recommends updating the package and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473297 identifying Chainguard chromium-lang packages affected by CVE-2026-95312, a Chrome Passwords information leak allowing cross-origin data disclosure through crafted HTML after renderer compromise. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473277 identifying Chainguard Chromium packages affected by CVE-2026-95315, a high-severity Chrome Aura use-after-free flaw that could allow a local attacker to execute arbitrary code outside the sandbox through UI interaction. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473321 identifying Chainguard Chromium packages affected by CVE-2026-95309, a Chrome iOS UI misrepresentation flaw allowing UI spoofing through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473288 identifying Chainguard chromium-lang packages affected by CVE-2026-102305, a Chrome iOS SignIn UI misrepresentation flaw allowing UI spoofing through crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473302 identifying Chainguard chromium-lang packages affected by CVE-2026-102306, a Chrome Bluetooth use-after-free flaw that could allow arbitrary code execution outside the sandbox through crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473333 identifying Chainguard Chromium packages affected by CVE-2026-95384, a medium-severity Chrome Transactions Platform race condition that could leak sensitive information through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473338 identifying Chainguard chromium-lang packages affected by CVE-2026-102328, a high-severity Chrome V8 type-confusion flaw allowing arbitrary code execution inside the sandbox through crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473305 identifying Chainguard Chromium packages affected by CVE-2026-95342, a Chrome V8 missing-authorization flaw allowing web origin policy bypass through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports available exploits, but not active exploitation.
Tenable published plugin 473332 identifying Chainguard Chromium packages affected by CVE-2026-95346, a medium-severity Chrome Chromoting UI misrepresentation flaw allowing UI spoofing through crafted network traffic. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports available exploits, but not active exploitation.
Tenable published plugin 473296 identifying Chainguard Chromium packages affected by CVE-2026-95289, a Chrome Scroll incorrect-authorization flaw allowing cross-origin data disclosure through crafted HTML and social engineering. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports available exploits, but not active exploitation.
Tenable published plugin 473325 identifying Chainguard Chromium packages affected by CVE-2026-102318, a Chrome WebGL out-of-bounds read flaw allowing memory reads outside the sandbox through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473339 identifying Chainguard chromium-lang packages affected by CVE-2026-102316, a Chrome Views use-after-free flaw allowing arbitrary code execution outside the sandbox through crafted HTML and social engineering. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473279 identifying Chainguard chromium-lang packages affected by CVE-2026-95365, a high-severity Chrome IndexedDB type-confusion flaw allowing arbitrary code execution inside the sandbox through crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473294 identifying Chainguard chromium-lang packages affected by CVE-2026-95380, a Chrome V8 type-confusion flaw allowing arbitrary code execution inside the sandbox through social engineering and crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473292 identifying Chainguard chromium-lang packages affected by CVE-2026-95367, a Chrome DataTransfer information leak requiring renderer compromise, social engineering, and crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473270 identifying Chainguard chromium-lang packages affected by CVE-2026-102308, a Chrome Views use-after-free flaw allowing arbitrary code execution outside the sandbox through crafted HTML and social engineering. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473364 identifying Chainguard chromium-lang packages affected by CVE-2026-95361, a Chrome DevTools confused-deputy flaw allowing web origin policy bypass through crafted HTML and social engineering. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473284 identifying Chainguard Chromium packages affected by CVE-2026-95340, a Chrome PictureInPicture incorrect-authorization flaw allowing web origin policy bypass through crafted HTML and social engineering. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473271 identifying Chainguard chromium-docker-selenium-compat packages affected by CVE-2026-95304, a high-severity Chrome V8 out-of-bounds write flaw allowing arbitrary code execution inside the sandbox through crafted HTML. It recommends updating the package and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473344 identifying Chainguard chromium-docker-selenium-compat packages affected by CVE-2026-95277, a Chrome Views use-after-free flaw that could allow arbitrary code execution outside the sandbox through crafted HTML. It recommends updating the package and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473289 identifying Chainguard chromium-lang packages affected by CVE-2026-95298, a high-severity Chrome Browser use-after-free flaw allowing a local attacker to execute arbitrary code outside the sandbox through UI interaction. It recommends updating to version 154.0.8037.92-r0 or later and reports available exploits, but not active exploitation.
Tenable published plugin 473363 identifying Chainguard chromium-lang packages affected by CVE-2026-102314, a Chrome TabStrip UI misrepresentation flaw allowing UI spoofing through crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473283 identifying Chainguard chromium-docker-selenium-compat packages affected by CVE-2026-95287, a Chrome Navigation missing-authorization flaw allowing site-isolation bypass through crafted HTML after renderer compromise. It recommends updating the package and related packages to version 154.0.8037.92-r0 or later and reports available exploits, but not active exploitation.
Tenable published plugin 473272 identifying Chainguard Chromium packages affected by CVE-2026-95338, a high-severity PDFium use-after-free vulnerability allowing arbitrary code execution inside the sandbox through a crafted PDF file. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473286 identifying Chainguard chromium-lang packages affected by CVE-2026-102325, a Chrome Skia uninitialized-resource flaw allowing cross-origin data disclosure through crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473267 identifying Chainguard Chromium packages affected by CVE-2026-95382, a medium-severity Chrome Auth input-validation flaw allowing sensitive-information disclosure after renderer compromise and social engineering. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473319 identifying Chainguard chromium-lang packages affected by CVE-2026-95288, a low-severity Chrome iOS UI misrepresentation flaw allowing UI spoofing through crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473352 identifying Chainguard Chromium packages affected by CVE-2026-95364, a Chrome Passwords input-validation flaw allowing UI spoofing through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports available exploits, but not active exploitation.
Tenable published plugin 473311 identifying Chainguard Chromium packages affected by CVE-2026-102303, a Chrome Android GPU uninitialized-resource flaw allowing cross-origin data disclosure through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473306 identifying Chainguard chromium-docker-selenium-compat packages affected by CVE-2026-95336, a medium-severity Chrome Transactions Platform flaw allowing sensitive-information disclosure through crafted HTML and social engineering. It recommends updating the package and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473342 identifying Chainguard Chromium packages affected by CVE-2026-102309, a FullScreen use-after-free vulnerability allowing arbitrary code execution outside the sandbox through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473341 identifying Chainguard Chromium packages affected by CVE-2026-102324, a high-severity PictureInPicture use-after-free flaw that could allow arbitrary code execution outside the sandbox after renderer compromise. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473265 identifying Chainguard Chromium packages affected by CVE-2026-95360, a medium-severity Chrome Editing race condition that could expose sensitive information through crafted HTML and social engineering. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473335 identifying Chainguard chromium-lang packages affected by CVE-2026-95372, a high-severity Chrome Chromecast use-after-free flaw that could allow arbitrary code execution outside the sandbox after renderer compromise. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473365 identifying Chainguard chromium-lang packages affected by CVE-2026-102310, a Chrome Payments missing-authorization flaw allowing web origin policy bypass after renderer compromise. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473298 identifying Chainguard chromium-lang packages affected by CVE-2026-102301, a high-severity Chrome GPU out-of-bounds write flaw that could allow arbitrary code execution outside the sandbox after renderer compromise. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473337 identifying Chainguard chromium-lang packages affected by CVE-2026-95308, a low-severity Chrome Metrics integer overflow that could permit out-of-sandbox memory reads after renderer compromise. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473312 identifying Chainguard Chromium packages affected by CVE-2026-95303, a Chrome SmartCard incomplete-cleanup flaw allowing system access restrictions to be bypassed through crafted HTML and social engineering. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473361 identifying Chainguard Chromium packages affected by CVE-2026-95344, a Chrome DevTools race condition allowing site-isolation bypass through social engineering and a crafted extension. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports available exploits, but not active exploitation.
Tenable published plugin 473274 identifying Chainguard Chromium packages affected by CVE-2026-95334, a Chrome WebProtect incorrect-reference-resolution flaw that could allow arbitrary code execution outside the sandbox after renderer compromise. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473347 identifying Chainguard chromium-lang packages affected by CVE-2026-95369, a Chrome XML-handling flaw allowing arbitrary code execution inside the sandbox through crafted HTML. It recommends updating chromium-lang and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473293 identifying Chainguard chromium-docker-selenium-compat packages affected by CVE-2026-95359, a Chrome Android GPU uninitialized-resource flaw permitting out-of-sandbox memory reads after renderer compromise. It recommends updating to version 154.0.8037.92-r0 or later and reports available exploits, but not active exploitation.
Tenable published plugin 473353 identifying Chainguard Chromium packages affected by CVE-2026-95320, a medium-severity Chrome Navigation missing-authorization flaw allowing address-bar spoofing after renderer compromise. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473345 identifying Chainguard chromium-lang packages affected by CVE-2026-95294, a medium-severity Chrome Browser UI misrepresentation flaw allowing UI spoofing through crafted HTML and social engineering. It recommends updating to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473350 identifying Chainguard Chromium packages affected by CVE-2026-95297, a missing-authorization flaw in Chrome's Contextual Tasks feature that allows web origin policy bypass through crafted HTML. It recommends updating Chromium and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473357 identifying Chainguard chromium-docker-selenium-compat packages affected by CVE-2026-95353, a Chrome Bindings use-after-free flaw allowing arbitrary code execution inside the sandbox through crafted HTML. It recommends updating the package and related packages to version 154.0.8037.92-r0 or later and reports no known available exploits.
Tenable published plugin 473358 identifying Chainguard chromium-lang packages affected by CVE-2026-95341, a Chrome Desktop input-validation flaw that could allow sandbox escape after renderer compromise. It recommends updating to version 154.0.8037.92-r0 or later and reports no known available exploits.
The Canadian Centre for Cyber Security published advisory AV26-984 for Google Chrome Stable Channel for Desktop, identifying versions before 154.0.8037.92/.93 on Windows and macOS and 154.0.8037.92 on Linux as affected. It urged users and administrators to review Google's advisory and apply available updates.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102331, a critical ANGLE buffer overflow affecting Chrome on Android that could allow a remote attacker to execute arbitrary code outside the sandbox through crafted HTML. Tenable recommends updating Chromium and related packages and reports no known available exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102326, a high-severity V8 type-confusion vulnerability allowing a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page with user interaction. Tenable recommends updating Chromium and related packages and reports no known available exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102301, a high-severity GPU out-of-bounds write vulnerability that could let an attacker with an already-compromised renderer execute arbitrary code outside the sandbox through crafted HTML. Tenable recommends updating Chromium and related packages and reports no known available exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102302, a high-severity V8 buffer overflow allowing a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page. Tenable recommends updating Chromium and related packages and reports no known available exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102299, a high-severity V8 type confusion vulnerability allowing a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92-1~deb12u1 addresses CVE-2026-102300, a high-severity WebGPU uninitialized-resource vulnerability allowing a remote attacker to obtain cross-origin data through a crafted HTML page. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102324, a high-severity PictureInPicture use-after-free vulnerability that could allow an attacker with an already-compromised renderer process to execute arbitrary code outside the sandbox through crafted HTML. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102328, a high-severity V8 type confusion vulnerability allowing a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page with user interaction. Tenable recommends updating Chromium and related packages and reports no known available exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102311, an uninitialized-resource vulnerability in Chrome's GPU component on Android that allows an attacker with an already-compromised renderer process to read memory outside the sandbox through crafted HTML. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102307, an uninitialized-resource vulnerability in Dawn affecting Chrome on Android that allows a remote attacker to read memory outside the sandbox through a crafted HTML page. Tenable recommends updating Chromium and related packages and reports no known available exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102309, a FullScreen use-after-free vulnerability that could allow a remote attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102308, a Views use-after-free vulnerability that could allow a remote attacker using social engineering and a crafted HTML page to execute arbitrary code outside the browser sandbox. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102320, a missing-authorization vulnerability in CORS that allows an attacker with an already-compromised renderer process to bypass web origin policy through a crafted HTML page. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102315, a Media uninitialized-resource vulnerability affecting Chrome on Windows that lets an attacker with a compromised renderer read memory outside the sandbox through crafted HTML. Tenable recommends updating Chromium and related packages and reports no known available exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102330, an incorrect-authorization vulnerability in SiteIsolation that lets an attacker who has compromised the renderer process bypass web origin policy through a crafted HTML page. Tenable recommends updating Chromium and related packages and reports no known available exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102317, a high-severity Mojo improper privilege management vulnerability affecting Chrome on Windows that could allow a local attacker to execute arbitrary code outside the browser sandbox. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102316, a Views use-after-free vulnerability that could allow a remote attacker using social engineering and a crafted HTML page to execute arbitrary code outside the browser sandbox. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102306, a Bluetooth use-after-free vulnerability that could allow a remote attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102325, an uninitialized-resource vulnerability in Skia that allows a crafted HTML page to obtain cross-origin data. Tenable recommends updating Chromium and related packages and reports no known exploits.
An Echo Chromium security update to version 154.0.8037.92 addresses CVE-2026-102329, a WebUI cross-site scripting vulnerability allowing a remote attacker to bypass web origin policy into a privileged page through crafted HTML. Tenable recommends updating Chromium and related packages and reports no known exploits.
Tenable identifies an Echo Chromium security update to version 154.0.8037.92 addressing CVE-2026-102313, an uninitialized-resource vulnerability in ANGLE that can allow a crafted HTML page to read memory outside the sandbox. It recommends updating the Chromium library and related packages and reports no known exploits.
CVE-2026-102303 was published as an uninitialized-resource vulnerability in Chrome's GPU component on Android before version 154.0.8037.92, allowing a remote attacker to obtain cross-origin data through a crafted HTML page with user interaction. Chromium classified it as High severity; Tenable assigned a CVSS v3 score of 4.3 and reported no known available exploits.
CVE-2026-102312 was published as a UI misrepresentation vulnerability in Chrome's Omnibox on Android before version 154.0.8037.92, allowing a remote attacker to spoof the address bar through a crafted HTML page with user interaction. Chromium classified it as High severity; Tenable reported a CVSS v3 score of 4.3 and no known exploits.
CVE-2026-102305 was published as a UI misrepresentation vulnerability in Chrome's SignIn component on iOS before version 154.0.8037.92, allowing a remote attacker to spoof UI elements through a crafted HTML page with user interaction. Chromium classified it as Low severity; Tenable assigned a CVSS v3 score of 5.4 and reported no known available exploits.
CVE-2026-102310 was published as a missing-authorization vulnerability in Chrome's Payments component affecting versions before 154.0.8037.92, allowing an attacker who has already compromised the renderer process to bypass web origin policy through a crafted HTML page. Chromium classified it as Low severity; Tenable assigned a CVSS v3 score of 6.5 and reported no known exploits.
CVE-2026-102319 was published as an uninitialized-resource vulnerability in Chrome's GPU component affecting versions before 154.0.8037.92. An attacker who had already compromised the renderer process could use a crafted HTML page to read memory outside the sandbox; Chromium classified it as High severity, and Tenable reported no known exploits.
CVE-2026-102304 was published as a use-after-free vulnerability in Chrome's Passwords component affecting versions before 154.0.8037.92, allowing a remote attacker to execute arbitrary code outside the sandbox through a crafted HTML page. Chromium classified it as High severity; Tenable assigned a CVSS v3 score of 9.6 and reported no known exploits.
CVE-2026-102314 was published as a UI misrepresentation vulnerability in Chrome's TabStrip affecting versions before 154.0.8037.92, allowing a remote attacker to spoof browser UI elements through a crafted HTML page with user interaction. Chromium classified it as Low severity, while Tenable assigned a CVSS v3 score of 5.4 and reported no known available exploits.
CVE-2026-102321 was published as a high-severity V8 type confusion vulnerability affecting Google Chrome versions before 154.0.8037.92, allowing a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page with user interaction. Tenable lists a CVSS v3 score of 8.8 and reports no known exploits.
CVE-2026-102327 was published as an incorrect-authorization vulnerability affecting Chrome WebView on Android before version 154.0.8037.92. An attacker who had already compromised the renderer process could potentially execute arbitrary code outside the sandbox using a crafted HTML page; Chromium classified the vulnerability as Low severity, and Tenable reported no known exploits.
CVE-2026-102318 was published as an out-of-bounds read vulnerability affecting Chrome versions before 154.0.8037.92, allowing a remote attacker to use a crafted HTML page to read memory outside the sandbox with user interaction. Chromium classified the vulnerability as High severity; Tenable reported no known exploits.
CVE-2026-102331 was published as an unpatched vulnerability affecting Debian Linux 12.0, 13.0, and 14.0, with Debian's Chromium package identified in the affected context. Tenable assessed it as network-reachable with low attack complexity, no required privileges, required user interaction, and high confidentiality, integrity, and availability impact; no public exploits were known.
CVE-2026-102325 was published as an unpatched vulnerability affecting Chromium on Debian Linux 12.0, 13.0, and 14.0. Tenable assessed it as network-accessible with low attack complexity, no required privileges, required user interaction, and low confidentiality impact; no known exploits were reported.
CVE-2026-102323 was published as an unpatched vulnerability affecting the Debian Chromium package on Debian Linux 12.0, 13.0, and 14.0. Tenable assessed it as network-accessible with low attack complexity, no required privileges, required user interaction, and high confidentiality, integrity, and availability impact; no known exploits were reported.
CVE-2026-102313 was published as an unpatched vulnerability affecting Debian Linux 12.0, 13.0, and 14.0, with Chromium referenced in affected package data. Tenable assessed it as network-accessible with low attack complexity, no required privileges, required user interaction, and low confidentiality impact; no known public exploits were available.
CVE-2026-102329 was published as an unpatched vulnerability affecting Debian Linux 12.0, 13.0, and 14.0. Tenable reported no known exploits and assessed it as network-accessible with required user interaction and low confidentiality and integrity impact.
Researcher @mfx reported CVE-2026-102331, a critical buffer-overflow vulnerability in Chrome's ANGLE component, to Google.
Guyana National CIRT published advisory ADV2026_645 concerning Chrome Stable Channel for Desktop vulnerabilities addressed by Google's September 29 update. It recommended that users and administrators review and apply the update, without identifying specific CVEs or reporting exploitation activity.
Debian issued DSA-6535 concerning the Chromium source package in Debian trixie, referencing CVE-2026-102299 through CVE-2026-102321 and CVE-2026-102323 through CVE-2026-102331. The supplied material provides no vulnerability details, affected or fixed versions, or exploitation information.
Debian issued DLA-4811 for its Chromium source package, associating the update with CVE-2026-102299 through CVE-2026-102321 and CVE-2026-102323 through CVE-2026-102331. The reference does not state affected or fixed versions, vulnerability details, or exploitation status.
Google released Chrome Stable 154.0.8037.92/.93 for Windows and macOS and 154.0.8037.92 for Linux, remediating 32 security vulnerabilities. The fixes include critical ANGLE buffer overflow CVE-2026-102331 and 26 high-severity issues affecting V8, GPU, WebGPU, Mojo, Bluetooth, WebUI, Passwords, and other components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
50 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.