Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37)
Multiple Vulnerabilities in Google Chrome Patched in Stable (TL-2026-2662) is a medium-severity software vulnerability, first published 2026-09-26. It has no confirmed attribution, affects Google Chrome (Desktop - Linux), references 3 CVEs (CVE-2026-95274 to CVE-2026-95376, CVE-2026-95380 to CVE-2026-95382, CVE-2026-95384 to CVE-2026-95385), maps to 7 MITRE ATT&CK techniques (T1203, T1204.001, T1211), and is covered by 9 detection rules and 10 indicators of compromise.
Key facts for TL-2026-2662
- Threat ID
- TL-2026-2662
- Severity
- MEDIUM
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-09-26
- Last reviewed
- 2026-09-26
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 10
Google's Chrome 154 Stable Channel Update (154.0.8037.57/.58) fixes 108 security vulnerabilities, including 11 Critical memory-corruption bugs in ANGLE, WebGL, the GPU process, and ServiceWorker/Fullscreen/WindowDialog/AdFilter, plus 25 High-severity flaws. GovCERT.HK's Security Alert A26-09-37 warns that a remote attacker could exploit these issues via a crafted web page to achieve remote code execution, denial of service, or tampering; no in-the-wild exploitation or public PoC has been reported, and none of the affected CVEs currently appear in CISA's KEV catalog.
How Multiple Vulnerabilities in Google Chrome Patched in Stable works
On 2026-09-22, Google shipped a Chrome Stable Channel Update for Desktop bringing Chrome to version 154.0.8037.57 on Linux and 154.0.8037.57/.58 on Windows and macOS. The release addresses 108 security vulnerabilities: 11 rated Critical, 25 rated High, 47 rated Medium, and 25 rated Low. Google's own security team found 76 of the 108 issues internally; the remaining 32 were reported by external researchers, who collectively received $18,000 in bug-bounty payouts. Chrome for Android (154.0.8037.57) and Chrome for iOS (154.0.8037.55) received the same fixes within the same release window.
The 11 Critical-rated bugs are concentrated in Chrome's graphics and process-isolation stack: three buffer overflows in ANGLE (Chrome's cross-platform graphics abstraction layer, including CVE-2026-95350, credited to a STAR Labs SG Pte. Ltd. team of Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, and Pan Zhenpeng for a $5,000 bounty), a buffer overflow and an out-of-bounds write in WebGL, two out-of-bounds writes in the GPU process (one, CVE-2026-95357, paid a $2,500 bounty), and four use-after-free bugs spanning ServiceWorker, Fullscreen, WindowDialog, and AdFilter. Among the 25 High-severity fixes are an out-of-bounds write (CVE-2026-95304) and a type-confusion bug (CVE-2026-95306) in the V8 JavaScript engine; CVE-2026-95306 was credited to 'OpenAI Codex Security,' a notable early example of an AI-assisted vulnerability-research effort receiving public credit in a Chrome security bulletin.
GovCERT.HK (Hong Kong's Government Computer Emergency Response Team) published Security Alert A26-09-37 on 2026-09-23, summarizing the update and warning that 'a remote attacker could entice a user to open a web page with specially crafted content on a vulnerable browser to exploit the vulnerabilities,' with potential impact of remote code execution, denial of service, or tampering. The advisory lists the affected CVEs as three ranges (CVE-2026-95274 to CVE-2026-95376, CVE-2026-95380 to CVE-2026-95382, CVE-2026-95384 to CVE-2026-95385) rather than a fully enumerated list, and does not assign a CVSS score or classify the alert as a 'High Threat' bulletin. Google's practice of withholding technical bug details until a majority of the installed base has updated means most individual CVEs in this batch are not yet indexed in NVD. As of this research, none of the CVE-2026-953xx range appears in CISA's Known Exploited Vulnerabilities catalog, and no public proof-of-concept exploit code has surfaced; this distinguishes the batch from the unrelated, earlier V8 type-confusion zero-day (CVE-2026-85046, fixed in Chrome 152.0.7977.82/.83 and added to CISA KEV on 2026-09-04), which is a separate, already-patched issue from a prior release and is not part of this advisory.
Because Chromium is the shared upstream for Chrome, Chromium-based third-party browsers (Microsoft Edge, Brave, Opera, Vivaldi) and forks (Ungoogled Chromium, which shipped a matching 154.0.8037.57-1 build) inherit the same vulnerable ANGLE/WebGL/GPU/V8/ServiceWorker code paths and require their own vendor updates to receive equivalent fixes.
MITRE ATT&CK techniques used in TL-2026-2662
Execution
T1203 Exploitation for Client Execution; T1204.001 Malicious Link
Stealth
T1211 Exploitation for Stealth
Impact
T1499.004 Application or System Exploitation
Resource Development
T1587.004 Exploits; T1588.006 Vulnerabilities; T1608.004 Drive-by Target
Affected products and versions in Multiple Vulnerabilities in Google Chrome Patched in Stable
- Google — Chrome (Desktop - Linux)
Vulnerable versions: prior to 154.0.8037.57
Fixed in: 154.0.8037.57 - Google — Chrome (Desktop - Windows)
Vulnerable versions: prior to 154.0.8037.57
Fixed in: 154.0.8037.57; 154.0.8037.58 - Google — Chrome (Desktop - macOS)
Vulnerable versions: prior to 154.0.8037.57
Fixed in: 154.0.8037.57; 154.0.8037.58 - Google — Chrome for Android
Vulnerable versions: prior to 154.0.8037.57
Fixed in: 154.0.8037.57 - Google — Chrome for iOS
Vulnerable versions: prior to 154.0.8037.55
Fixed in: 154.0.8037.55
Remediation for Multiple Vulnerabilities in Google Chrome Patched in Stable
Patches
- Google Chrome 154.0.8037.57 (Desktop, Linux)
- Google Chrome 154.0.8037.57/.58 (Desktop, Windows and macOS)
- Google Chrome for Android 154.0.8037.57
- Google Chrome for iOS 154.0.8037.55
Immediate actions
- Update Google Chrome to 154.0.8037.57 or later on Linux, and 154.0.8037.57/.58 or later on Windows and macOS, via chrome://settings/help, then relaunch the browser
- Update Chrome for Android to 154.0.8037.57 or later
- Update Chrome for iOS to 154.0.8037.55 or later
- Update any Chromium-based browser (Microsoft Edge, Brave, Opera, Vivaldi) or fork (Ungoogled Chromium) to its own vendor build that incorporates the equivalent ANGLE/WebGL/GPU/V8/ServiceWorker fixes
Workarounds
- No effective workaround short of updating; disabling JavaScript, WebGL, or hardware/GPU acceleration may reduce exposure to specific bug classes but does not substitute for patching and is not recommended as a standing control
Longer-term hardening
- Enforce timely browser patching via enterprise policy (e.g. Chrome Browser Cloud Management) rather than relying solely on end-user auto-update
- Keep Chrome's sandboxing and Site Isolation settings at their default/enforced levels to limit the impact of renderer- and GPU-process memory-corruption bugs
- Track GovCERT.HK and Chrome release-blog advisories for this recurring monthly-to-biweekly Chrome vulnerability-batch pattern
CVEs associated with Multiple Vulnerabilities in Google Chrome Patched in Stable
CVE-2026-95274 to CVE-2026-95376, CVE-2026-95380 to CVE-2026-95382, CVE-2026-95384 to CVE-2026-95385
Weaknesses (CWE) in Multiple Vulnerabilities in Google Chrome Patched in Stable
CWE-120, CWE-787, CWE-416, CWE-843
Timeline of Multiple Vulnerabilities in Google Chrome Patched in Stable
- Coverage noted the update would roll out gradually over the following days and weeks rather than reaching all users simultaneously, consistent with Chrome's standard staged-rollout practice.
- Google shipped Chrome for Android 154.0.8037.57 in the same window, addressing the same vulnerability set as the desktop release.
- Google published a Chrome Stable Channel Update for Desktop, shipping Chrome 154.0.8037.57 (Linux) and 154.0.8037.57/.58 (Windows and macOS), fixing 108 security vulnerabilities including 11 Critical and 25 High-severity issues.
- Security press reported that Google found 76 of the 108 fixed bugs internally, while 32 were reported by external researchers who received a combined $18,000 in bug bounties, including a $5,000 award for the ANGLE buffer overflow CVE-2026-95350 (STAR Labs SG Pte. Ltd.) and public credit to 'OpenAI Codex Security' for the V8 type-confusion flaw CVE-2026-95306.
- GovCERT.HK published Security Alert A26-09-37, 'Multiple Vulnerabilities in Google Chrome,' summarizing the update as a routine (non-High-Threat) advisory and directing users to patch to 154.0.8037.57 or later.
- Google shipped Chrome for iOS 154.0.8037.55, extending the fix set to Apple's iOS/iPadOS build of Chrome.
- As of this research, none of the CVE-2026-95274 to CVE-2026-95385 range appears in CISA's Known Exploited Vulnerabilities catalog, and NVD has not yet published individual CVE records for the batch, consistent with Google's practice of withholding technical bug details until most users have updated.
Sources cited for Multiple Vulnerabilities in Google Chrome Patched in Stable
- Security Alert (A26-09-37): Multiple Vulnerabilities in Google Chrome
- Stable Channel Update for Desktop
- Update Chrome: 108 security fixes for desktop, new release for Android
- Chrome 154 fixes 108 security flaws, including 11 critical bugs
- Chrome Patches 108 Vulnerabilities Including Critical Flaws that Enable Code Execution Attacks
- Chrome 154 Patches 108 Vulnerabilities
- Chrome 154 Release Patches 108 Security Vulnerabilities
- Chrome 154: 108 Patches, 11 Critical GPU and V8 Flaws
- Known Exploited Vulnerabilities Catalog
More in vulnerability
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40
- Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses (CVE-2026-13016, CVE-2026-86857-86860)
- Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin skip_block_zeroing residual block reuse
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS
Detection coverage for TL-2026-2662
As of 2026-09-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2662 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.