Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.4 Browsers CVE-2026-103630 CVE-2026-102316 CVE-2026-103626 CVE-2026-102309

Google Chrome Patches Eight High-Severity Vulnerabilities Across Two Stable Channel Updates

Google shipped two Chrome Stable channel updates in late September and early October 2026 fixing eight vulnerabilities, including use-after-free, out-of-bounds write, buffer overflow, and incorrect authorization issues. All allow remote code execution outside the sandbox via a crafted HTML page.

AI summary

Google released two consecutive Stable channel updates for Chrome on desktop, addressing a total of eight distinct vulnerabilities disclosed between late September and early October 2026. The issues span several browser components, including FedCM, Views, FileSystem, FullScreen, ANGLE, WebGL, Passwords, and Bluetooth. All eight carry a CVSS base score of 9.6 and were rated High or Critical severity by the Chromium security team. Each could allow a remote attacker to execute arbitrary code outside the browser sandbox via a specially crafted HTML page, with some requiring a degree of social engineering to succeed.

Eight vulnerabilities fixed in two Chrome updates

Google published two Stable channel updates for Chrome on desktop: one on September 29, 2026 (fixing CVE-2026-102316, CVE-2026-102309, CVE-2026-102331, CVE-2026-102304, and CVE-2026-102306, resolved in version 154.0.8037.92) and one on October 2, 2026 (fixing CVE-2026-103630, CVE-2026-103626, and CVE-2026-103628, resolved in version 154.0.8037.97). All eight vulnerabilities are described as allowing a remote attacker to execute, or potentially execute, arbitrary code outside the sandbox via a crafted HTML page.

Mix of memory-safety and authorization flaws

Six of the eight issues are use-after-free vulnerabilities (CWE-416) affecting the FedCM (CVE-2026-103630), Views (CVE-2026-102316), FullScreen (CVE-2026-102309), Passwords (CVE-2026-102304), and Bluetooth (CVE-2026-102306) components. One is a buffer overflow (CWE-122) in ANGLE on Android (CVE-2026-102331), one is an out-of-bounds write (CWE-787) in WebGL (CVE-2026-103628), and one is an incorrect authorization flaw (CWE-863) in the FileSystem component on Windows (CVE-2026-103626). All eight share the same CVSS vector, indicating network-based attack access, low attack complexity, no privileges required, required user interaction, and a scope change with high impact to confidentiality, integrity, and availability.

Potential for sandbox escape and code execution

Each vulnerability is rated with a CVSS base score of 9.6, reflecting the potential severity if exploited: a successful attack could let a remote party execute arbitrary code outside Chrome's sandbox protections, which is designed to contain the impact of a compromised renderer or web page. Several of the descriptions note that exploitation requires social engineering (CVE-2026-102316, CVE-2026-103626) or general user interaction (loading a crafted HTML page), which reduces but does not eliminate practical risk. None of the eight vulnerabilities are currently listed as known exploited, and no public exploit code is reported in the fact package.

Chrome users on desktop and Android

The affected product is Google Chrome. Most of the fixed issues apply broadly to Chrome; CVE-2026-103626 specifically affects Chrome on Windows, and CVE-2026-102331 specifically affects Chrome on Android. The remaining vulnerabilities do not specify a platform restriction in the available descriptions.

Versions prior to the fixes

Chrome versions prior to 154.0.8037.92 are affected by CVE-2026-102316, CVE-2026-102309, CVE-2026-102331, CVE-2026-102304, and CVE-2026-102306. Chrome versions prior to 154.0.8037.97 are affected by CVE-2026-103630, CVE-2026-103626, and CVE-2026-103628.

Fixed in Chrome 154.0.8037.92 and 154.0.8037.97

Google addressed five of the vulnerabilities in Chrome version 154.0.8037.92 and the remaining three in version 154.0.8037.97, both released via the Stable channel for desktop. No workaround other than updating is described in the available sources.

Update Chrome immediately

Site owners and users should ensure Google Chrome is updated to at least version 154.0.8037.97, which includes the fixes from both Stable channel releases covered in this briefing. Chrome typically updates automatically, but administrators should verify the installed version across managed fleets, particularly on Windows and Android endpoints referenced in the platform-specific advisories.

PatchBriefing score

6.4 / 10 · Medium

Official CVSS: 9.6

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

All eight vulnerabilities carry a Patchwire score of 6.4, driven primarily by a CVSS base score of 9.6 for each (contributing 5.28 points), reflecting a network attack vector, low complexity, no privileges required, and high impact to confidentiality, integrity, and availability. An additional 0.6 points reflect the unauthenticated remote attack path, and 0.5 points reflect the very high popularity of the affected product (Google Chrome). None of these vulnerabilities are currently known to be exploited in the wild, and no public exploit code has been reported, which is why the score does not reach higher tiers despite the high CVSS base scores.

Affected versions

≥ 154.0.8037.97
patched
≥ 154.0.8037.92
patched
≥ 154.0.8037.97
patched
≥ 154.0.8037.92
patched
≥ 154.0.8037.92
patched
≥ 154.0.8037.97
patched
≥ 154.0.8037.92
patched
≥ 154.0.8037.92
patched

Reported fixes

Google addressed five of the vulnerabilities in Chrome version 154.0.8037.92 and the remaining three in version 154.0.8037.97, both released via the Stable channel for desktop. No workaround other than updating is described in the available sources.

How this was built

10 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Patches Eight High-Severity Vulnerabilities Across Two Stable Channel Updates
1 article · 10 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email