Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.4 Browsers CVE-2026-95283 CVE-2026-95350 CVE-2026-95362 CVE-2026-95345

Google Chrome 154.0.8037.57 Fixes Eight Vulnerabilities, Including Two Critical/High-Severity Sandbox Escapes

Google has released Chrome 154.0.8037.57 for desktop and Android, fixing eight vulnerabilities including buffer overflows, use-after-free issues, type confusion bugs, a CSRF flaw, and an XML implementation issue. Two of the Android-specific issues could allow code execution outside the sandbox.

AI summary

Google has published a Stable Channel update for Chrome, version 154.0.8037.57, addressing eight distinct vulnerabilities disclosed on the same day. The affected components span the Chrome rendering and scripting stack, including V8, ANGLE, DevTools, XML handling, and internal memory management code. All eight issues were assigned CVSS base scores of 8.8 or 9.6, reflecting their potential for remote exploitation. This briefing summarizes what is known from the vendor release notes and the corresponding NVD entries.

What Happened

Google released a Stable Channel update for Chrome (desktop) and a corresponding Android update bringing both to version 154.0.8037.57. The update resolves eight separate vulnerabilities: two buffer overflows (CVE-2026-95283, CVE-2026-95350) specific to Chrome on Android, three use-after-free or type-confusion memory safety issues affecting the browser generally (CVE-2026-95345, CVE-2026-95282, CVE-2026-95306, CVE-2026-95380), a cross-site request forgery issue in DevTools (CVE-2026-95362), and an inappropriate implementation issue in XML handling (CVE-2026-95369). All issues were disclosed via Google's Chrome Releases blog alongside NVD database entries.

Technical Cause

The vulnerabilities stem from several distinct underlying bug classes. CVE-2026-95283 (CWE-122, buffer overflow in 'Tint') and CVE-2026-95350 (CWE-122, buffer overflow in 'ANGLE') are both memory corruption issues specific to the Android build of Chrome. CVE-2026-95345 (CWE-416, use after free in 'Actor') and CVE-2026-95282 (CWE-416, use after free in 'Platform') involve memory being accessed after it has been freed. CVE-2026-95306 and CVE-2026-95380 (both CWE-843, type confusion in 'V8') relate to the JavaScript engine treating data as an incorrect type. CVE-2026-95369 (CWE-841, inappropriate implementation in 'XML') involves flawed logic in XML processing. CVE-2026-95362 (CWE-352, cross-site request forgery in DevTools) allows an attacker to bypass the web origin policy. All of the memory-safety and logic issues are reachable via a crafted HTML page; the DevTools issue additionally requires social engineering to trick a user into an action.

Why It Matters

Several of these vulnerabilities carry a CVSS base score of 9.6 or 8.8, indicating high-impact, network-exploitable issues requiring only user interaction (e.g., visiting a malicious page) and no privileges. The two Android-specific buffer overflow issues (CVE-2026-95283 and CVE-2026-95350) are particularly notable because successful exploitation is described as allowing code execution outside the browser's sandbox — meaning an attacker could potentially affect the device beyond the browser process itself. CVE-2026-95350 was rated 'Critical' by Chromium's own internal severity classification. The remaining memory-safety bugs allow code execution inside the sandbox, which is a serious issue but contained by Chrome's sandboxing architecture. The DevTools CSRF issue (CVE-2026-95362) could let an attacker bypass the web origin policy through social engineering.

Who Is Affected

All users running Google Chrome versions prior to 154.0.8037.57 are affected. Two of the eight vulnerabilities (CVE-2026-95283 and CVE-2026-95350) are specific to Chrome on Android; the remaining six affect Chrome generally, which includes the desktop channel referenced in the vendor's Stable Channel Update announcement.

Affected Versions

All versions of Google Chrome prior to 154.0.8037.57 are affected by at least one of the eight described vulnerabilities. The fact package does not specify a lower bound for the affected version range, so users on any earlier release should assume exposure and update promptly.

Fixes and Mitigation

Google has released Chrome version 154.0.8037.57, which contains fixes for all eight vulnerabilities described in this briefing. No workarounds or mitigations other than updating are described in the available source material.

Recommended Action

Update Google Chrome to version 154.0.8037.57 or later as soon as possible, on both desktop and Android. Chrome typically updates automatically, but users and administrators should verify the installed version via the browser's About page and restart the browser to apply the update. Organizations managing Chrome deployments at scale should confirm that the update has propagated across all endpoints.

PatchBriefing score

6.4 / 10 · Medium

Official CVSS: 9.6

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

The individual Patchwire scores (6.4 for the two Android-specific buffer overflow issues, 5.9 for the remaining six) are derived primarily from each vulnerability's CVSS base score (9.6 or 8.8), combined with a modest contribution from the fact that these are unauthenticated, network-exploitable issues affecting a very widely used product. None of the eight vulnerabilities are currently flagged as known exploited or associated with public exploit code, and no EPSS score was available, which limits the scores compared to actively exploited vulnerabilities. The two Android-specific buffer overflow issues score somewhat higher due to their sandbox-escape potential.

Affected versions

≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched

Reported fixes

Google has released Chrome version 154.0.8037.57, which contains fixes for all eight vulnerabilities described in this briefing. No workarounds or mitigations other than updating are described in the available source material.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome 154.0.8037.57 Fixes Eight Vulnerabilities, Including Two Critical/High-Severity Sandbox Escapes
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email