Google Chrome 154.0.8037.92 Patches 32 Security Flaws, Including a Critical ANGLE Bug
Chrome's Stable channel moves to 154.0.8037.92/.93 (Windows/Mac) and 154.0.8037.92 (Linux), fixing 32 security issues including a critical buffer overflow in ANGLE and a high-severity privilege management flaw in Mojo.
Google has released Chrome 154.0.8037.92 (and .93 on Windows/Mac) to the Stable channel, with the Linux build rolling out over the coming days to weeks. This update addresses 32 security fixes, among them a critical-severity vulnerability, making it a release that site owners and developers relying on Chrome or Chromium-based browsers should prioritize.
What's new
This build consolidates 32 security fixes identified internally and through Google's vulnerability reward program. Two issues have been disclosed with specifics so far: a critical buffer overflow in ANGLE (CVE-2026-102331, reported by external researcher mfx on August 24, 2026) and a high-severity improper privilege management flaw in Mojo (CVE-2026-102317, found by Google itself on May 28, 2026). ANGLE is Chrome's graphics translation layer, used to render WebGL and other GPU-accelerated content, while Mojo is the inter-process communication system underpinning Chrome's sandboxed architecture — meaning both components sit close to the browser's security boundaries. As is standard practice, Google is withholding full bug details and links for many of the remaining fixes until a majority of users have updated, and may keep restrictions in place longer if a fix touches a shared third-party library still being patched elsewhere.
Why it matters for your stack
Buffer overflows in rendering components like ANGLE can potentially be leveraged for memory corruption and, in the worst case, remote code execution if chained with other bugs, which is why this one is rated critical. Privilege management flaws in core subsystems like Mojo can undermine the sandboxing that normally limits the damage a compromised renderer process can do. For teams that embed Chromium (via Electron, CEF, or similar), or that simply rely on Chrome for day-to-day browsing and web app testing, this release closes exposure that could otherwise be exploited through malicious or compromised web content.
How to update
Chrome typically updates itself automatically in the background; you can force a check and apply the update immediately via the browser menu under Help > About Google Chrome, which also triggers a restart to complete the install. Enterprises managing Chrome through policy or a controlled rollout should prioritize pushing this version given the critical-severity fix included, and should plan equivalent updates for any Chromium-based browsers or embedded Chromium runtimes in their stack.
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email