Medium · 5.5 Browsers CVE-2026-95344 CVE-2026-95326 CVE-2026-95285 CVE-2026-95278
Google Chrome Stable Update Fixes Seven Vulnerabilities, Including High-Severity V8 and Aura Flaws
Google has released Chrome 154.0.8037.57 for Desktop, patching seven vulnerabilities affecting components including V8, Aura, DevTools, Bluetooth, WebView, and WakeLock. Two issues carry a Chromium-assessed 'High' severity.
AI summary
Google has published a Stable Channel update for Chrome on Desktop, addressing seven distinct vulnerabilities across multiple browser components. The fixed version is 154.0.8037.57. The issues range from race conditions and use-after-free bugs to missing authorization checks, with Chromium-assigned severity ratings of High, Medium, and Low. None of the vulnerabilities are currently known to be exploited in the wild, and no public exploit code has been reported for any of them.
What happened
Google released a Stable Channel update for Chrome on Desktop that resolves seven separate vulnerabilities. These affect the following components: V8 (CVE-2026-95280), Aura (CVE-2026-95315), DevTools (CVE-2026-95344 and CVE-2026-95376), Bluetooth (CVE-2026-95326), WebView on Android (CVE-2026-95285), and WakeLock (CVE-2026-95278). The vulnerabilities include race conditions, a use-after-free, missing authorization checks, an externally controlled reference, and incomplete cleanup.
Technical causes
The root causes vary by component. CVE-2026-95280 (V8) and CVE-2026-95344 (DevTools) are race conditions (CWE-367/CWE-362) that can allow sandbox code execution or site isolation bypass respectively. CVE-2026-95315 (Aura) is a use-after-free (CWE-416) that could allow code execution outside the sandbox following local UI interaction. CVE-2026-95285 (WebView) and CVE-2026-95278 (WakeLock) are missing authorization issues (CWE-862) that could allow a compromised renderer process to bypass web origin policy or system access restrictions. CVE-2026-95326 (Bluetooth) stems from incomplete cleanup (CWE-459), and CVE-2026-95376 (DevTools) involves an externally controlled reference (CWE-610) that could be abused via crafted network traffic by an adjacent attacker using social engineering.
Why it matters
Two of the seven vulnerabilities (CVE-2026-95280 in V8 and CVE-2026-95315 in Aura) are rated 'High' by Chromium's own severity scale, indicating a greater potential impact if exploited, including arbitrary code execution inside or outside the browser sandbox. The remaining five are rated Medium or Low by Chromium, though CVSS base scores for several of these reach 8.0 or higher, reflecting a high impact on confidentiality, integrity, or availability under certain conditions. None of the seven vulnerabilities are listed as known to be exploited, and no public exploit code has been reported.
Who is affected
All users running Google Chrome on Desktop prior to version 154.0.8037.57 are affected. One vulnerability, CVE-2026-95285, specifically concerns Chrome's WebView component on Android.
Affected and fixed versions
All versions of Google Chrome prior to 154.0.8037.57 are affected by these vulnerabilities. The fact package does not specify a precise lower bound for each affected range, so users should treat any version older than the fixed release as vulnerable.
Fixes and mitigation
Google has released Chrome 154.0.8037.57 for Desktop, which resolves all seven vulnerabilities described in this briefing. Chrome typically updates automatically on restart; users can also trigger an update manually via the browser's settings menu.
Recommended action
Update Google Chrome to version 154.0.8037.57 or later as soon as possible. Restart the browser after the update is applied to ensure the fix takes effect. Organizations managing Chrome deployments via enterprise policy should verify that the update has been pushed to all managed endpoints, including any Android devices relying on Chrome's WebView component.
PatchBriefing score
5.5 / 10 · Medium
Official CVSS: 8.0
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Why this score
The patchwire scores for these seven vulnerabilities range from approximately 4.8 to 5.5, driven primarily by their CVSS base scores (7.5–8.4) and a small additional contribution from Chrome's very large install base (product popularity factor). None of the vulnerabilities are flagged as known exploited or associated with public exploit code, which keeps the scores in a moderate range despite high CVSS base scores. Score variation among the seven CVEs reflects differences in attack vector (network vs. local vs. adjacent), need for user interaction, and whether the attack can be carried out by an unauthenticated remote party.
Affected versions
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
Reported fixes
Google has released Chrome 154.0.8037.57 for Desktop, which resolves all seven vulnerabilities described in this briefing. Chrome typically updates automatically on restart; users can also trigger an update manually via the browser's settings menu.
How this was built
8 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email