Medium · 6.4 Browsers CVE-2026-102308 CVE-2026-102302 CVE-2026-103623 CVE-2026-103631
Google Chrome Patches Four High-Severity Vulnerabilities, Including a Sandbox Escape
Google shipped two Chrome Stable updates in late September and early October 2026 fixing four high-severity memory-safety vulnerabilities. One flaw allows code execution outside the browser sandbox; the other three allow code execution within the sandbox. All require a user to visit a crafted HTML page.
AI summary
Between September 29 and October 2, 2026, Google released two Chrome Stable channel updates addressing four high-severity vulnerabilities in the browser's rendering and media-handling components. Three of the flaws allow an attacker to execute arbitrary code confined within Chrome's security sandbox, while one allows an attacker to break out of the sandbox entirely. All four require a user to visit or be lured to a specially crafted HTML page, and one additionally relies on social engineering. No evidence of active exploitation or public proof-of-concept exploits has been reported for any of these issues.
What happened
Google released two Chrome Stable updates in close succession. The first, version 154.0.8037.92, fixed a use-after-free vulnerability in the Views component (CVE-2026-102308) and a buffer overflow in V8 (CVE-2026-102302). The second, version 154.0.8037.97, fixed a use-after-free vulnerability in MediaStream (CVE-2026-103623) and a buffer overflow in WebRTC (CVE-2026-103631). All four are rated High severity by the Chromium project and are exploitable via a crafted HTML page.
Technical cause
CVE-2026-102308 and CVE-2026-103623 are use-after-free bugs (CWE-416), where code continues to reference memory after it has been freed, potentially allowing an attacker to hijack program execution. CVE-2026-102302 is a buffer overflow in the V8 JavaScript engine (CWE-121), and CVE-2026-103631 is a buffer overflow in WebRTC (CWE-122); both involve writing data beyond the bounds of an allocated buffer, which can corrupt memory and lead to code execution.
Why it matters
CVE-2026-102308, the Views use-after-free, is the most serious of the four: it is described as allowing code execution outside the sandbox, meaning a successful exploit could escape Chrome's primary containment mechanism and affect the underlying system, though it requires social engineering to trigger. The remaining three vulnerabilities (CVE-2026-102302, CVE-2026-103623, CVE-2026-103631) allow code execution inside the sandbox, which still poses a significant risk but is constrained by Chrome's additional sandbox protections. All four can be triggered simply by loading a malicious web page, with no further authentication needed by the attacker.
Who is affected
All users running Google Chrome on desktop prior to the fixed versions are affected. Given Chrome's extremely large installed base, this impacts a very wide population of individual and organizational users.
Affected and fixed versions
CVE-2026-102308 and CVE-2026-102302 affect Chrome versions prior to 154.0.8037.92. CVE-2026-103623 and CVE-2026-103631 affect Chrome versions prior to 154.0.8037.97. No specific starting version for the affected range was provided in the vendor data; the advisories only specify the fixed versions.
Fixes and mitigation
Google has released fixes for all four vulnerabilities. Chrome version 154.0.8037.92 resolves CVE-2026-102308 and CVE-2026-102302. Chrome version 154.0.8037.97 resolves CVE-2026-103623 and CVE-2026-103631. Chrome's auto-update mechanism will typically apply these updates automatically once the browser is restarted.
Recommended action
Site owners and developers should ensure Chrome is updated to at least version 154.0.8037.97, which includes fixes for all four vulnerabilities described here. Check the browser's About page to confirm the installed version and restart Chrome to apply any pending update. Organizations managing Chrome deployments via policy should verify that automatic updates are not disabled and push the update promptly given the sandbox-escape potential of CVE-2026-102308.
PatchBriefing score
6.4 / 10 · Medium
Official CVSS: 9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Why this score
The patchwire scores (6.4 for CVE-2026-102308, and 5.9 each for CVE-2026-102302, CVE-2026-103623, and CVE-2026-103631) primarily reflect their high CVSS base scores (9.6 and 8.8 respectively), which indicate network-exploitable, low-complexity attacks with high impact on confidentiality, integrity, and availability. Additional contribution comes from the fact that exploitation does not require attacker authentication and from Chrome's very large install base. None of the four have confirmed active exploitation, known ransomware association, or public exploit code, and EPSS data was not available, which keeps the scores below the maximum despite the severe technical impact.
Affected versions
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.97
- patched
- ≥ 154.0.8037.97
- patched
Reported fixes
Google has released fixes for all four vulnerabilities. Chrome version 154.0.8037.92 resolves CVE-2026-102308 and CVE-2026-102302. Chrome version 154.0.8037.97 resolves CVE-2026-103623 and CVE-2026-103631. Chrome's auto-update mechanism will typically apply these updates automatically once the browser is restarted.
How this was built
6 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email