Medium · 5.7 Browsers CVE-2026-102324 CVE-2026-102301 CVE-2026-103624 CVE-2026-102317
Google Chrome Patches Five High-Severity Vulnerabilities, Including Sandbox Escape Flaws
Google has fixed five high-severity vulnerabilities in Chrome, including use-after-free and out-of-bounds write bugs that could allow attackers who have already compromised the renderer process to execute code outside the browser sandbox. No active exploitation has been reported.
AI summary
Google has released two Stable Channel updates for Chrome on desktop that address five vulnerabilities rated High by the Chromium security team. The issues span different components of the browser, including PictureInPicture, GPU handling, Contextual Tasks, Mojo, and WebView. Several of the flaws could allow an attacker who has already compromised a renderer process to escape the browser sandbox and potentially execute arbitrary code. None of these vulnerabilities are currently known to be actively exploited.
Five vulnerabilities fixed in two Chrome updates
Google published two Stable Channel updates for Chrome on desktop, released on 2026-09-29 and 2026-10-02, addressing five distinct vulnerabilities. The first update fixed CVE-2026-102324 (use-after-free in PictureInPicture), CVE-2026-102301 (out-of-bounds write in GPU), CVE-2026-102317 (improper privilege management in Mojo, on Windows), and CVE-2026-102327 (incorrect authorization in WebView, on Android). The second update, released a few days later, fixed CVE-2026-103624 (use-after-free in Contextual Tasks, on Windows).
Memory safety and authorization bugs
The vulnerabilities stem from different underlying weaknesses. CVE-2026-102324 and CVE-2026-103624 are use-after-free bugs (CWE-416) in the PictureInPicture and Contextual Tasks components respectively. CVE-2026-102301 is an out-of-bounds write (CWE-787) in the GPU component. CVE-2026-102317 is an improper privilege management issue (CWE-269) in Mojo, Chrome's inter-process communication system. CVE-2026-102327 is an incorrect authorization flaw (CWE-863) in WebView. According to the vendor descriptions, most of these flaws require an attacker to have already compromised the renderer process (via a crafted HTML page) before they can be leveraged to escape the sandbox; CVE-2026-102317 instead requires local access via a local program.
Potential for sandbox escape and code execution
Four of the five vulnerabilities (CVE-2026-102324, CVE-2026-102301, CVE-2026-103624, CVE-2026-102317) describe a path to executing arbitrary code outside Chrome's sandbox, which is a significant escalation from a typical renderer-level compromise. CVE-2026-102327 involves incorrect authorization in WebView on Android with the same stated potential outcome. All carry a CVSS base score of 7.5 or higher, reflecting high impact on confidentiality, integrity, and availability if successfully exploited.
Chrome users on desktop, Windows, and Android
CVE-2026-102324, CVE-2026-102301, and CVE-2026-102327 affect Google Chrome generally, with CVE-2026-102327 specifically noted on Android. CVE-2026-103624 and CVE-2026-102317 are specifically noted as affecting Google Chrome on Windows. All fixes apply to Google Chrome; no other products are listed in the available data.
Versions affected and fixed
Chrome versions prior to 154.0.8037.92 are affected by CVE-2026-102324, CVE-2026-102301, CVE-2026-102317, and CVE-2026-102327. Chrome versions prior to 154.0.8037.97 are affected by CVE-2026-103624. No lower bound of the affected version range was specified in the available data.
Fixed versions available
Google has released fixes for all five vulnerabilities. CVE-2026-102324, CVE-2026-102301, CVE-2026-102317, and CVE-2026-102327 are fixed in Chrome 154.0.8037.92. CVE-2026-103624 is fixed in Chrome 154.0.8037.97.
Update Chrome as soon as possible
Site owners and users should ensure Google Chrome is updated to at least version 154.0.8037.97, which includes fixes for all five vulnerabilities described here, since it supersedes the earlier 154.0.8037.92 release. Chrome typically updates automatically, but a manual check via the browser's settings menu is advised to confirm the update has been applied.
PatchBriefing score
5.7 / 10 · Medium
Official CVSS: 8.3
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Why this score
Each vulnerability received a Patchwire score of 5.2–5.7, driven primarily by CVSS base scores ranging from 7.5 to 8.6. These scores reflect high potential impact (arbitrary code execution outside the sandbox) but are tempered by the lack of confirmed exploitation in the wild, no public exploit code, and access complexity that in most cases requires an attacker to have already compromised the renderer process or, for CVE-2026-102317, to have local access. No EPSS data was available to factor into likelihood estimates.
Affected versions
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.97
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
Reported fixes
Google has released fixes for all five vulnerabilities. CVE-2026-102324, CVE-2026-102301, CVE-2026-102317, and CVE-2026-102327 are fixed in Chrome 154.0.8037.92. CVE-2026-103624 is fixed in Chrome 154.0.8037.97.
How this was built
7 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email