Medium · 5.7 Browsers CVE-2026-95341 CVE-2026-95334 CVE-2026-95354 CVE-2026-95274
Google Chrome Stable Update Fixes Eight Security Vulnerabilities
Google has released a Chrome Stable channel update addressing eight vulnerabilities, including several use-after-free and input validation issues that could allow code execution or sandbox escape. Update to version 154.0.8037.57.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
AI summary
Google has published a Stable Channel update for Google Chrome on Desktop that resolves eight distinct security vulnerabilities identified as CVE-2026-95341, CVE-2026-95334, CVE-2026-95354, CVE-2026-95274, CVE-2026-95276, CVE-2026-95348, CVE-2026-95314 and CVE-2026-95301. All eight issues are fixed in Chrome version 154.0.8037.57. The vulnerabilities span multiple Chrome components, including DevTools, Bluetooth, HID, Extensions, Themes, and internal components referred to as 'WebProtect' and 'Verifier'. According to Google's advisory, several of these bugs could be exploited by a remote attacker who had already compromised the renderer process, potentially leading to code execution outside the sandbox or bypass of site isolation and system access restrictions.
What Happened
Google released a Stable Channel update for Chrome on Desktop that patches eight separate vulnerabilities. The flaws involve use-after-free conditions, improper input validation, incorrect reference resolution, improper output encoding, incorrect authorization, and missing authorization across different Chrome components (DevTools, Bluetooth, HID, Extensions, Themes, and two components referred to in the advisories as 'WebProtect' and 'Verifier'). All eight issues were disclosed and fixed together in the same release.
Technical Cause
The vulnerabilities stem from a range of underlying weaknesses: CWE-416 (use after free) affects the Verifier and Bluetooth components (CVE-2026-95354, CVE-2026-95348); CWE-20 (improper input validation) affects Desktop and Themes components (CVE-2026-95341, CVE-2026-95276); CWE-706 (incorrect reference resolution) affects WebProtect (CVE-2026-95334); CWE-116 (improper output encoding) affects DevTools (CVE-2026-95274); CWE-863 (incorrect authorization) affects HID (CVE-2026-95314); and CWE-862 (missing authorization) affects Extensions (CVE-2026-95301). Most of these issues require that an attacker has already compromised the renderer process, and exploitation typically involves crafted network traffic or a crafted HTML page.
Why It Matters
Several of these vulnerabilities (CVE-2026-95341, CVE-2026-95354, CVE-2026-95274, CVE-2026-95348) are rated by Chromium as Medium to High severity and could allow a remote attacker, after first compromising the renderer process, to execute arbitrary code outside Chrome's sandbox. Others, such as CVE-2026-95314 and CVE-2026-95301, could allow bypass of system access restrictions or site isolation, which are key protections separating untrusted web content from the rest of the system and from other sites. Because these are chained exploitation scenarios starting from an already-compromised renderer, they represent a meaningful risk primarily in combination with a separate renderer-level exploit, but still warrant prompt patching given Chrome's broad user base.
Who Is Affected
All users running Google Chrome on Desktop prior to version 154.0.8037.57 are affected. The advisory does not specify particular operating systems, so this update should be assumed to apply broadly across Desktop platforms supported by Chrome Stable.
Affected Versions
Chrome versions prior to 154.0.8037.57 are affected by these eight vulnerabilities.
Fixes and Mitigation
Google has fixed all eight vulnerabilities in Chrome version 154.0.8037.57, distributed via the Stable Channel update for Desktop. No separate workarounds or mitigations are described in the advisory; updating is the sole remediation path mentioned.
Recommended Action
Update Google Chrome to version 154.0.8037.57 or later as soon as possible. Chrome typically updates automatically, but users and administrators should verify the installed version via the browser's About page and restart the browser to apply the update. Organizations managing Chrome deployments at scale should confirm that managed update policies have rolled out this version.
PatchBriefing score
5.7 / 10 · Medium
Official CVSS: 8.3
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Why this score
The Patchwire scores for these vulnerabilities range from 5.6 to 5.7, driven primarily by CVSS base scores of 8.1 to 8.3. These scores reflect high potential impact (confidentiality, integrity, and in some cases availability) combined with network attack vector, but the scores are moderated by the requirement for high attack complexity or user interaction, and by the lack of any evidence of known exploitation, public exploit code, or EPSS data in the fact package. No known exploited or ransomware association has been reported for any of these CVEs.
Affected versions
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
Reported fixes
Google has fixed all eight vulnerabilities in Chrome version 154.0.8037.57, distributed via the Stable Channel update for Desktop. No separate workarounds or mitigations are described in the advisory; updating is the sole remediation path mentioned.
How this was built
9 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email