Medium · 5.8 Browsers CVE-2026-95333 CVE-2026-95351 CVE-2026-95319 CVE-2026-95322
Google Chrome 154.0.8037.57 Fixes Eight High-Severity Vulnerabilities, Including Multiple Use-After-Free Flaws
Google has shipped Chrome 154.0.8037.57 to fix eight vulnerabilities, most rated High or Critical by Chromium's own severity scale, including several use-after-free bugs that could allow code execution outside the sandbox.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
AI summary
Google has released Chrome version 154.0.8037.57 for desktop, addressing eight distinct vulnerabilities disclosed on the same day. The affected components span Metrics, Views, Printing, GPU, Navigation, HID, and Chromecast subsystems. Several of these issues are use-after-free bugs (CWE-416), one is an out-of-bounds write (CWE-787), one is an authorization flaw (CWE-863), and one is an input validation issue (CWE-20). All eight carry a CVSS base score in the 8.1–8.3 range and were disclosed via Chrome's stable channel release notes and corroborated by NVD entries.
What happened
Google published a stable channel update for Chrome on desktop, fixing eight vulnerabilities: CVE-2026-95333 (Metrics, use-after-free, Chromium severity Medium), CVE-2026-95351 (Views, use-after-free, Chromium severity High), CVE-2026-95319 (Printing, use-after-free, Chromium severity Low), CVE-2026-95322 (GPU, out-of-bounds write, Chromium severity Critical, affecting Android), CVE-2026-95355 (Navigation, incorrect authorization, Chromium severity High, affecting iOS), CVE-2026-95335 (HID, use-after-free, Chromium severity High), CVE-2026-95372 (Chromecast, use-after-free, Chromium severity High), and CVE-2026-95381 (Printing, improper input validation, Chromium severity Medium).
Technical cause
Five of the eight issues are use-after-free vulnerabilities (CWE-416), a memory management flaw where a program continues to use a pointer after the associated memory has been freed, which can lead to memory corruption and potential code execution. One issue (CVE-2026-95322) is an out-of-bounds write (CWE-787) in the GPU component. CVE-2026-95355 is an incorrect authorization flaw (CWE-863) in the Navigation component. CVE-2026-95381 stems from improper input validation (CWE-20) in the Printing component. Most descriptions indicate exploitation requires an attacker who has already compromised the renderer process and delivers a crafted HTML page, except CVE-2026-95333, which is described as exploitable via crafted network traffic without requiring a prior renderer compromise.
Why it matters
All eight vulnerabilities carry CVSS base scores between 8.1 and 8.3, reflecting high confidentiality, integrity, and availability impact if exploited. Several are rated High or Critical on Chromium's internal severity scale. Successful exploitation could allow an attacker to execute arbitrary code outside Chrome's sandbox, which is a significant escalation beyond the renderer's normally restricted execution context. Given Chrome's installed base, these issues affect a very large number of desktop, Android, and iOS users depending on the specific vulnerability.
Who is affected
Users running Google Chrome prior to version 154.0.8037.57 are affected. CVE-2026-95322 is specifically noted as affecting Chrome on Android, and CVE-2026-95355 is specifically noted as affecting Chrome on iOS. The remaining vulnerabilities apply to Chrome generally as described in the vendor advisory.
Affected versions
All eight vulnerabilities affect Google Chrome versions prior to 154.0.8037.57. No specific starting version for the affected range was provided in the fact package.
Fixes and mitigation
Google has released Chrome 154.0.8037.57 for desktop, which fixes all eight vulnerabilities described in this briefing. No additional mitigations or workarounds were disclosed in the available source material.
Recommended action
Update Google Chrome to version 154.0.8037.57 or later as soon as possible. Chrome typically updates automatically, but users and administrators should verify the installed version via the browser's About page and restart the browser to apply the update. Given the number and severity of the fixed issues, prioritize this update across managed fleets.
PatchBriefing score
5.8 / 10 · Medium
Official CVSS: 8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Why this score
Each vulnerability received a patchwire_score of approximately 5.7–5.8, driven primarily by CVSS base scores of 8.1–8.3 (contributing roughly 4.46–4.57 points), combined with smaller contributions for unauthenticated remote attack vectors (0.6), no user interaction where applicable (0.2), and product popularity (0.5). None of the issues are flagged as known exploited, associated with public exploit code, or tied to ransomware activity, and EPSS data was not available for any of them. The scores reflect the technical severity of the flaws and Chrome's broad installed base rather than any confirmed in-the-wild exploitation.
Affected versions
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
Reported fixes
Google has released Chrome 154.0.8037.57 for desktop, which fixes all eight vulnerabilities described in this briefing. No additional mitigations or workarounds were disclosed in the available source material.
How this was built
9 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email