Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe
154.0.8037.97
RELEASE SECURITY Browsers Google Chrome · released October 2, 2026 · covered October 2, 2026

Google Chrome 154.0.8037.97 fixes 11 security issues, including a critical WebGL flaw

Chrome's Stable channel moves to 154.0.8037.97/.98 (Windows/Mac) and 154.0.8037.97 (Linux), patching 11 security vulnerabilities, including a critical out-of-bounds write in WebGL and a high-severity authorization flaw in the FileSystem API.

11 security fixes 1 critical WebGL bug (CVE-2026-103628) 1 high-severity FileSystem flaw Stable for Windows, Mac, Linux
AI summary

Google has released Chrome 154.0.8037.97 (.98 on Windows and Mac) to the Stable channel, with the Linux build rolling out under the same version number over the coming days and weeks. This update addresses 11 security fixes, including a critical-severity bug, making it a release that site owners and developers relying on Chrome or Chromium-based browsers should prioritize.

What's fixed in this release

Google's release notes confirm 11 security fixes in this build. Two have been disclosed with specifics: CVE-2026-103628, a critical out-of-bounds write vulnerability in WebGL, and CVE-2026-103626, a high-severity incorrect authorization issue in the FileSystem component. Both were reported internally by Google, on August 21 and August 26, 2026 respectively. As is standard practice, Google is withholding details on the remaining fixes until most users have updated, and may keep restrictions longer where a fix depends on a third-party library shared with other projects.

Why it matters for your stack

An out-of-bounds write in WebGL is a serious class of memory-safety bug that can potentially be leveraged for code execution simply by visiting a malicious or compromised web page, since WebGL content runs automatically in many sites. The FileSystem authorization issue could allow unintended access to data that should otherwise be restricted. Any product embedding Chromium, or any environment where users browse the open web, should treat this update as a priority rather than routine maintenance.

How to update

Chrome updates automatically in the background on most systems; a full restart of the browser applies the new version immediately. You can also trigger the check manually via Settings > About Chrome, which will download and prompt for a restart if an update is pending. For managed fleets, IT teams should confirm that enterprise policies aren't delaying rollout, given the critical-severity fix included here.

Synthesized by AI from 1 source · updated 1 hour ago
Sources · merged by AI 1 total
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email