Medium · 6.4 Browsers CVE-2026-103630 CVE-2026-102316 CVE-2026-103626 CVE-2026-102309
Google Chrome Patches Eight High-Severity Vulnerabilities Across Two Stable Channel Updates
Google shipped two Chrome Stable channel updates in late September and early October 2026 fixing eight vulnerabilities, including use-after-free, out-of-bounds write, buffer overflow, and incorrect authorization issues. All allow remote code execution outside the sandbox via a crafted HTML page.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 4d ago · view ↗
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 5d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 5d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
AI summary
Google released two consecutive Stable channel updates for Chrome on desktop, addressing a total of eight distinct vulnerabilities disclosed between late September and early October 2026. The issues span several browser components, including FedCM, Views, FileSystem, FullScreen, ANGLE, WebGL, Passwords, and Bluetooth. All eight carry a CVSS base score of 9.6 and were rated High or Critical severity by the Chromium security team. Each could allow a remote attacker to execute arbitrary code outside the browser sandbox via a specially crafted HTML page, with some requiring a degree of social engineering to succeed.
Eight vulnerabilities fixed in two Chrome updates
Google published two Stable channel updates for Chrome on desktop: one on September 29, 2026 (fixing CVE-2026-102316, CVE-2026-102309, CVE-2026-102331, CVE-2026-102304, and CVE-2026-102306, resolved in version 154.0.8037.92) and one on October 2, 2026 (fixing CVE-2026-103630, CVE-2026-103626, and CVE-2026-103628, resolved in version 154.0.8037.97). All eight vulnerabilities are described as allowing a remote attacker to execute, or potentially execute, arbitrary code outside the sandbox via a crafted HTML page.
Mix of memory-safety and authorization flaws
Six of the eight issues are use-after-free vulnerabilities (CWE-416) affecting the FedCM (CVE-2026-103630), Views (CVE-2026-102316), FullScreen (CVE-2026-102309), Passwords (CVE-2026-102304), and Bluetooth (CVE-2026-102306) components. One is a buffer overflow (CWE-122) in ANGLE on Android (CVE-2026-102331), one is an out-of-bounds write (CWE-787) in WebGL (CVE-2026-103628), and one is an incorrect authorization flaw (CWE-863) in the FileSystem component on Windows (CVE-2026-103626). All eight share the same CVSS vector, indicating network-based attack access, low attack complexity, no privileges required, required user interaction, and a scope change with high impact to confidentiality, integrity, and availability.
Potential for sandbox escape and code execution
Each vulnerability is rated with a CVSS base score of 9.6, reflecting the potential severity if exploited: a successful attack could let a remote party execute arbitrary code outside Chrome's sandbox protections, which is designed to contain the impact of a compromised renderer or web page. Several of the descriptions note that exploitation requires social engineering (CVE-2026-102316, CVE-2026-103626) or general user interaction (loading a crafted HTML page), which reduces but does not eliminate practical risk. None of the eight vulnerabilities are currently listed as known exploited, and no public exploit code is reported in the fact package.
Chrome users on desktop and Android
The affected product is Google Chrome. Most of the fixed issues apply broadly to Chrome; CVE-2026-103626 specifically affects Chrome on Windows, and CVE-2026-102331 specifically affects Chrome on Android. The remaining vulnerabilities do not specify a platform restriction in the available descriptions.
Versions prior to the fixes
Chrome versions prior to 154.0.8037.92 are affected by CVE-2026-102316, CVE-2026-102309, CVE-2026-102331, CVE-2026-102304, and CVE-2026-102306. Chrome versions prior to 154.0.8037.97 are affected by CVE-2026-103630, CVE-2026-103626, and CVE-2026-103628.
Fixed in Chrome 154.0.8037.92 and 154.0.8037.97
Google addressed five of the vulnerabilities in Chrome version 154.0.8037.92 and the remaining three in version 154.0.8037.97, both released via the Stable channel for desktop. No workaround other than updating is described in the available sources.
Update Chrome immediately
Site owners and users should ensure Google Chrome is updated to at least version 154.0.8037.97, which includes the fixes from both Stable channel releases covered in this briefing. Chrome typically updates automatically, but administrators should verify the installed version across managed fleets, particularly on Windows and Android endpoints referenced in the platform-specific advisories.
PatchBriefing score
6.4 / 10 · Medium
Official CVSS: 9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Why this score
All eight vulnerabilities carry a Patchwire score of 6.4, driven primarily by a CVSS base score of 9.6 for each (contributing 5.28 points), reflecting a network attack vector, low complexity, no privileges required, and high impact to confidentiality, integrity, and availability. An additional 0.6 points reflect the unauthenticated remote attack path, and 0.5 points reflect the very high popularity of the affected product (Google Chrome). None of these vulnerabilities are currently known to be exploited in the wild, and no public exploit code has been reported, which is why the score does not reach higher tiers despite the high CVSS base scores.
Affected versions
- ≥ 154.0.8037.97
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.97
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.97
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
Reported fixes
Google addressed five of the vulnerabilities in Chrome version 154.0.8037.92 and the remaining three in version 154.0.8037.97, both released via the Stable channel for desktop. No workaround other than updating is described in the available sources.
How this was built
10 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email