Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)

Google Chrome 154 Update Fixes 32 Security Flaws Including (TL-2026-2803), also tracked as Chrome 154.0.8037.92 security update, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-09-30. It has no confirmed attribution, affects Google Chrome (Windows, macOS, Linux), references 32 CVEs (CVE-2026-102331, CVE-2026-102317, CVE-2026-102312), maps to 3 MITRE ATT&CK techniques (T1059.007, T1203, T1204.001), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-2803

Threat ID
TL-2026-2803
Also known as
Chrome 154.0.8037.92 security update, Chrome 154 stable channel update (2026-09-29)
Severity
CRITICAL
CVSS
9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-09-30
Last reviewed
2026-09-30
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, finance, health, education, critical-infrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
15

Google released Chrome 154.0.8037.92/.93 (Windows/macOS) and 154.0.8037.92 (Linux), fixing 32 vulnerabilities: one Critical heap buffer overflow in ANGLE (CVE-2026-102331, NVD CVSS 9.6), 25 High, 1 Medium and 5 Low across V8, GPU, WebGPU, WebGL, Dawn, Skia, Mojo and UI components. No active exploitation has been reported and the CVEs are not in CISA KEV.

How Google Chrome 154 Update Fixes 32 Security Flaws Including works

Google's Stable Channel Update for Desktop published on 2026-09-29 (reported by GBHackers on 2026-09-30) ships Chrome 154.0.8037.92/.93 for Windows and macOS and 154.0.8037.92 for Linux. It fixes 32 security issues: 1 Critical, 25 High, 1 Medium and 5 Low. This is a follow-up point release to the initial Chrome 154 stable build 154.0.8037.57/.58 of 2026-09-22, which fixed 108 flaws.

The Critical issue, CVE-2026-102331, is a buffer overflow in ANGLE, Chrome's graphics translation layer that maps WebGL/OpenGL ES calls onto native graphics APIs. The reporter is @mfx. NVD records it as CWE-122 (heap-based buffer overflow) with a CVSS 3.1 base score of 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), currently 'Awaiting Analysis'. The NVD description says a remote attacker could potentially execute arbitrary code outside the sandbox via a crafted HTML page. That text says 'Chrome on Android prior to 154.0.8037.92', while the desktop release notes list the same build number, so platform scope should be confirmed against the Chromium issue (551673541). Google has withheld technical details and no exploit scenario or PoC is public.

The 25 High-severity fixes are dominated by memory-safety and uninitialized-resource bugs. V8 has five type confusions (CVE-2026-102299, -102321, and three found by OpenAI Codex Security: -102323, -102326, -102328) and one buffer overflow (-102302). GPU, WebGPU, Dawn, Skia, ANGLE and Media have uninitialized-resource bugs (-102303, -102311, -102319, -102300, -102307, -102325, -102313, -102315). GPU has an out-of-bounds write (-102301) and WebGL an out-of-bounds read (-102318). Use-after-free bugs affect Bluetooth (-102306), Views (-102316, -102308), Passwords (-102304), FullScreen (-102309) and Picture-in-Picture (-102324). The rest are Mojo privilege mismanagement (-102317), Omnibox UI misrepresentation (-102312) and WebUI cross-site scripting (-102329). The Medium/Low group is authorization and UI-spoofing issues in CORS (-102320, Medium), Payments (-102310), WebView (-102327), Site Isolation (-102330), TabStrip (-102314) and SignIn (-102305).

Google has not indicated exploitation in the wild, and none of CVE-2026-102299 through CVE-2026-102331 appear in the CISA KEV catalog checked on 2026-09-30. Chrome V8 bugs CVE-2026-85046 and CVE-2026-87491 were added to KEV earlier in September 2026, so the browser engine remains an actively targeted surface. Because renderer, GPU and ANGLE memory-corruption bugs are typically chained with sandbox escapes once details are released, patch-gap risk rises after disclosure. Defenders should push the update to all Chromium-based browsers as downstream vendors ship it.

MITRE ATT&CK techniques used in TL-2026-2803

Execution

T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.001 Malicious Link

Affected products and versions in Google Chrome 154 Update Fixes 32 Security Flaws Including

  • Google — Chrome (Windows, macOS, Linux)
    Vulnerable versions: prior to 154.0.8037.92 (Linux); prior to 154.0.8037.92/.93 (Windows/macOS)
    Fixed in: 154.0.8037.92 (Linux); 154.0.8037.92/.93 (Windows/macOS)
  • Google — Chrome on Android (per NVD wording for CVE-2026-102331)
    Vulnerable versions: prior to 154.0.8037.92
    Fixed in: 154.0.8037.92

Remediation for Google Chrome 154 Update Fixes 32 Security Flaws Including

Patches

  • Chrome 154.0.8037.92/.93 Windows and macOS
  • Chrome 154.0.8037.92 Linux

Immediate actions

  • Update Google Chrome to 154.0.8037.92 (Linux) or 154.0.8037.92/.93 (Windows/macOS) or later, then relaunch the browser
  • Verify the version at chrome://settings/help across the managed fleet
  • Prioritise internet-facing and high-risk user endpoints (admins, developers, executives)

Workarounds

  • No vendor workaround published; where patching is delayed, restrict browsing to trusted sites and consider disabling hardware acceleration/WebGL for high-risk users as a temporary risk reduction

Longer-term hardening

  • Enforce browser auto-update and a short relaunch deadline via enterprise policy (RelaunchNotification / RelaunchNotificationPeriod)
  • Track downstream Chromium-based browsers (Edge, Brave, Opera, Vivaldi) and Electron apps for equivalent fixes
  • Keep Chrome site isolation and the renderer sandbox enabled; do not run with --no-sandbox

CVEs associated with Google Chrome 154 Update Fixes 32 Security Flaws Including

Weaknesses (CWE) in Google Chrome 154 Update Fixes 32 Security Flaws Including

CWE-122, CWE-416, CWE-843, CWE-908, CWE-787, CWE-125, CWE-79, CWE-862, CWE-863

Timeline of Google Chrome 154 Update Fixes 32 Security Flaws Including

  • CISA adds Chrome V8 type-confusion CVE-2026-85046 to KEV, showing the browser engine is an actively exploited surface earlier in the month
  • CISA adds Chrome V8 out-of-bounds write CVE-2026-87491 to KEV (remediation due 2026-09-23)
  • Chrome 154 stable ships as 154.0.8037.57/.58 with 108 security fixes, including 11 Critical (per PCWorld/Malwarebytes reporting)
  • Google publishes the Stable Channel Update for Desktop on the Chrome Releases blog with builds 154.0.8037.92/.93 (Windows/macOS) and 154.0.8037.92 (Linux)
  • None of CVE-2026-102299 to CVE-2026-102331 is present in the CISA KEV catalog; no in-the-wild exploitation reported
  • NVD publishes CVE-2026-102331 (CWE-122, CVSS 3.1 9.6) with status Awaiting Analysis; Chromium issue 551673541 referenced
  • GBHackers reports 32 security fixes: 1 Critical (ANGLE CVE-2026-102331), 25 High, 1 Medium, 5 Low; Google withholds technical details until most users update

Sources cited for Google Chrome 154 Update Fixes 32 Security Flaws Including

More in vulnerability

Detection coverage for TL-2026-2803

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2803 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats