Medium · 6.4 Browsers CVE-2026-95349 CVE-2026-95356 CVE-2026-95325 CVE-2026-95313
Google Chrome Stable Update Fixes Eight Critical/High-Severity Memory Safety Vulnerabilities
Google has released Chrome 154.0.8037.57 for desktop, fixing eight vulnerabilities rated Critical or High by Chromium's own severity classification, including buffer overflows and use-after-free bugs in WebGL, ANGLE, GPU, Video, Fullscreen, and WindowDialog components.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
AI summary
Google has published a Stable Channel Update for Chrome on desktop, addressing eight distinct memory-safety vulnerabilities across several browser components. All eight issues were independently assigned CVE identifiers and are fixed in Chrome 154.0.8037.57. The underlying bug classes are buffer overflows (CWE-122) and use-after-free conditions (CWE-416), both of which are common vectors for remote code execution in browsers. Two of the eight issues specifically affect the Android build of Chrome, while the remainder affect Chrome generally. [Source: 6406]
What happened
Google released a Stable Channel update for Chrome on desktop that bundles fixes for eight separate vulnerabilities, each tracked under its own CVE identifier: CVE-2026-95349 (buffer overflow in WebGL, Android), CVE-2026-95356 (use-after-free in WindowDialog), CVE-2026-95325 (use-after-free in ANGLE), CVE-2026-95313 (use-after-free in Fullscreen), CVE-2026-95299 (use-after-free in GPU), CVE-2026-95318 (buffer overflow in Video), CVE-2026-95284 (buffer overflow in ANGLE, Android), and CVE-2026-95281 (buffer overflow in ANGLE, Android). All eight are fixed in Chrome 154.0.8037.57. [Source: 6406]
Technical cause
The vulnerabilities fall into two underlying bug classes. Five are use-after-free issues (CWE-416), occurring in the WindowDialog, ANGLE, Fullscreen, and GPU components, where memory is accessed after it has already been freed, potentially allowing an attacker to manipulate freed memory to execute arbitrary code. Three are buffer overflow issues (CWE-122), occurring in WebGL, Video, and ANGLE, where data written past the bounds of allocated memory can corrupt adjacent memory and potentially lead to code execution. In each case, Google's advisory indicates a remote attacker could potentially execute arbitrary code outside Chrome's sandbox via a crafted HTML page. [Source: 6406, 27965, 27972, 27941, 27929, 27915, 27934, 27900, 27897]
Why this matters
Each of these eight vulnerabilities carries a CVSS base score of 9.6 (CVSS:3.1 vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), reflecting a network-exploitable flaw requiring low attack complexity and no privileges, with a scope change and high impact to confidentiality, integrity, and availability. Chromium's own internal severity rating classifies most of these as Critical, with two rated High and one rated Medium by Chromium's scale. Successful exploitation could allow an attacker to execute arbitrary code outside Chrome's sandbox, which is a significant escalation beyond typical browser-tab compromise. Because Chrome is used by an extremely large user base, even a single unpatched instance left running an older version represents meaningful risk exposure. [Source: 6406, 27965, 27972, 27941, 27929, 27915, 27934, 27900, 27897]
Who is affected
All users running Google Chrome prior to version 154.0.8037.57 are affected. Three of the eight vulnerabilities (CVE-2026-95349, CVE-2026-95284, CVE-2026-95281) are specifically noted as affecting the Android build of Chrome; the remaining five apply to Chrome generally as described in the advisories. The fact package does not specify whether other Chromium-based browsers are affected, so organizations using other Chromium derivatives should check with those vendors separately.
Affected and fixed versions
All eight vulnerabilities affect Chrome versions prior to 154.0.8037.57. Google has fixed all eight issues in Chrome 154.0.8037.57. No specific minimum affected version was provided in the source advisories beyond "prior to 154.0.8037.57."
Fixes and mitigation
Google has released Chrome 154.0.8037.57 for the Stable channel on desktop, which contains fixes for all eight vulnerabilities described in this briefing. No separate mitigations or workarounds were provided in the source material; updating to the fixed version is the documented remedy. [Source: 6406]
Recommended action
Update Google Chrome to version 154.0.8037.57 or later as soon as possible. Chrome typically updates automatically on restart, but administrators managing fleets of devices should verify that the update has been applied, particularly on Android devices where three of these issues specifically apply. No exploitation in the wild has been reported for any of these vulnerabilities based on the available facts, but given the Critical/High severity ratings and potential for sandbox-escape code execution, prompt patching is advised.
PatchBriefing score
6.4 / 10 · Medium
Official CVSS: 9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Why this score
Each of the eight vulnerabilities carries an identical CVSS 3.1 base score of 9.6, derived from a vector indicating network attack vector, low attack complexity, no privileges required, a change of scope, and high impact on confidentiality, integrity, and availability. The Patchwire score of 6.4 for each advisory is driven primarily by this high CVSS base score (contributing 5.28 points), with additional small contributions from the vulnerability being remotely exploitable without authentication (0.6) and from Chrome's very large installed user base (0.5). No points were added for known exploitation, public exploit code, or EPSS likelihood, as none of these factors were present in the data; all are marked as not known to be exploited and no public exploit is reported.
Affected versions
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
Reported fixes
Google has released Chrome 154.0.8037.57 for the Stable channel on desktop, which contains fixes for all eight vulnerabilities described in this briefing. No separate mitigations or workarounds were provided in the source material; updating to the fixed version is the documented remedy. [Source: 6406]
How this was built
9 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email