Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 Browsers CVE-2026-95286 CVE-2026-95373 CVE-2026-95338 CVE-2026-95304

Google Chrome Stable Update Fixes Seven High-Severity Memory Safety Vulnerabilities

Google released Chrome 154.0.8037.57 for Desktop, patching seven vulnerabilities including type confusion, use-after-free, and out-of-bounds write bugs across V8, DevTools, PDFium, WebAudio, Bindings, and IndexedDB that could allow remote code execution inside the sandbox.

AI summary

Google has published a Stable Channel update for Chrome Desktop, version 154.0.8037.57, addressing seven separate vulnerabilities across multiple browser components. All seven issues are memory-safety bugs — type confusion, use-after-free, and out-of-bounds write — rated High severity by Chromium's security team (one entry is marked Medium severity by Chromium but carries the same CVSS score in this package). Each could allow a remote attacker to execute arbitrary code inside Chrome's sandbox via a specially crafted HTML page or, in one case, a crafted PDF file.

Seven vulnerabilities patched in one Stable release

Google's Chrome Releases blog announced a Stable Channel update bringing Chrome Desktop to version 154.0.8037.57. The update bundles fixes for seven distinct CVEs: CVE-2026-95286 (type confusion in Bindings), CVE-2026-95373 (use-after-free in DevTools), CVE-2026-95338 (use-after-free in PDFium), CVE-2026-95304 (out-of-bounds write in V8), CVE-2026-95343 (use-after-free in WebAudio), CVE-2026-95353 (use-after-free in Bindings), and CVE-2026-95365 (type confusion in IndexedDB). Each affects Chrome prior to 154.0.8037.57.

Memory-safety bugs across multiple components

All seven issues stem from classic memory-safety weaknesses. CVE-2026-95286 and CVE-2026-95365 are type confusion flaws (CWE-843) in the Bindings and IndexedDB components, respectively. CVE-2026-95373, CVE-2026-95338, CVE-2026-95343, and CVE-2026-95353 are use-after-free flaws (CWE-416) in DevTools, PDFium, WebAudio, and Bindings. CVE-2026-95304 is an out-of-bounds write (CWE-787) in V8, Chrome's JavaScript engine. Six of the seven are triggered via a crafted HTML page; CVE-2026-95338 is triggered via a crafted PDF file processed by PDFium.

Potential for sandboxed code execution

Each vulnerability carries a CVSS score of 8.8 (CVSS:3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), reflecting network-exploitable, low-complexity attacks that require no privileges but do require user interaction (such as visiting a malicious page or opening a crafted PDF). Successful exploitation could let an attacker execute arbitrary code inside Chrome's sandbox, impacting confidentiality, integrity, and availability. Chromium's own severity ratings label six of the issues High and one (CVE-2026-95353) Medium, though the CVSS score reported for all seven in this package is identical. The description for CVE-2026-95365 notes exploitation would only 'potentially' allow code execution, and CVE-2026-95373 notes the attack requires social engineering.

Chrome Desktop users

Any user running Google Chrome on desktop prior to version 154.0.8037.57 is affected by these issues. No other products are named in this fact package.

Update to Chrome 154.0.8037.57

Google has fixed all seven vulnerabilities in Chrome 154.0.8037.57 for Desktop. No alternative mitigations or workarounds were provided in the vendor announcement.

Update now

Site owners and users should ensure Chrome updates to version 154.0.8037.57 or later, either automatically or by manually checking for updates via Chrome's settings menu. Because sandbox-escape-adjacent code execution bugs are involved, prompt patching is advised, particularly for environments where users routinely open untrusted web pages or PDF files.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Why this score

Each of the seven vulnerabilities carries a CVSS 3.1 base score of 8.8 (High), reflecting network attack vector, low attack complexity, no privileges required, but required user interaction, with high impact to confidentiality, integrity, and availability. The Patchwire score of 5.9 reflects the CVSS base contribution, a modest addition for the attack being unauthenticated and remote, and a small contribution for Chrome's extremely large install base, offset by the absence of confirmed exploitation in the wild, no public exploit code, and user interaction being required rather than automatic triggering.

Affected versions

≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched

Reported fixes

Google has fixed all seven vulnerabilities in Chrome 154.0.8037.57 for Desktop. No alternative mitigations or workarounds were provided in the vendor announcement.

How this was built

8 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Seven High-Severity Memory Safety Vulnerabilities
1 article · 8 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email