Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe
154.0.8037.151
RELEASE SECURITY Browsers Google Chrome · released October 9, 2026 · covered October 9, 2026

Google Chrome 154.0.8037.151 (ChromeOS Stable, OS 16805.33.0)

The ChromeOS Stable channel updates to OS version 16805.33.0 (Browser 154.0.8037.151) for most devices, including high-severity fixes that address a GPU use-after-free and a potential crosvm sandbox weakening.

Stable update to OS 16805.33.0 (Browser 154.0.8037.151) High: mali_kbase use-after-free may allow GPU-process to kgm High: Potential StartArcVm unvalidated wayland_server field— Android security fixes referenced in release notes
AI summary

The Stable channel for ChromeOS was updated to OS version 16805.33.0 (Browser version 154.0.8037.151) for most ChromeOS devices. Published on 2026-10-09, this release includes high-severity fixes affecting GPU memory handling and a potential sandbox weakening in crosvm. Device owners and administrators should plan to apply the update promptly.

What this release contains

This Stable-channel update moves ChromeOS to OS version 16805.33.0 and updates the browser to 154.0.8037.151 for most devices. The release notes call out high-severity third-party security fixes, including a mali_kbase use-after-free write in delete_hoarded_chunks that can allow GPU-process to kernel memory corruption, and a potential StartArcVm unvalidated wayland_server field that can lead to crosvm sandbox weakening. The notes also reference Android security fixes and list "Reported Bug Fixes: N/A."

Why it matters for your stack

The named fixes are high severity because they can affect process isolation and kernel memory integrity: a GPU-related use-after-free can permit corruption at a privileged layer, and issues that weaken the crosvm sandbox can increase the attack surface for virtualized components. For managed fleets and users handling sensitive data, applying these fixes reduces the risk of privilege escalation or kernel-impacting exploits.

How to update

ChromeOS devices on the Stable channel typically receive updates automatically. To ensure a device is up to date, open Settings > About Chrome OS and allow the device to check for and apply updates; a restart may be required to complete installation. If you run a managed fleet, verify roll-out status in your management console and follow your standard testing and deployment process before broad rollout.

Synthesized by AI from 1 source · updated 2 hours ago
Sources · merged by AI 1 total
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email