Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 Browsers CVE-2026-103622 CVE-2026-103625 CVE-2026-102323 CVE-2026-102328

Google Chrome: Seven High-Severity Vulnerabilities Fixed in Two Stable Channel Updates

Google shipped two Chrome Stable Channel updates in late September and early October 2026 that fix seven high-severity vulnerabilities in the V8 JavaScript engine and SVG rendering, including type confusion and use-after-free issues that could allow sandboxed remote code execution via a crafted HTML page.

AI summary

Google Chrome received two Stable Channel updates for desktop in late September and early October 2026, together addressing seven separate high-severity vulnerabilities. Six of the issues are type confusion flaws in the V8 JavaScript engine, and one is a use-after-free in SVG handling. All seven were rated by the Chromium project as High severity and share a similar exploitation pattern: a remote attacker could craft a malicious HTML page that, when visited, triggers memory corruption and allows arbitrary code execution inside Chrome's sandbox.

What happened

Google published two separate Stable Channel updates for Chrome on desktop. The first, released September 29, 2026, fixed five type confusion vulnerabilities in the V8 JavaScript engine: CVE-2026-102323, CVE-2026-102328, CVE-2026-102299, CVE-2026-102321, and CVE-2026-102326. The second, released October 2, 2026, fixed two additional high-severity issues: a use-after-free in SVG rendering (CVE-2026-103622) and a type confusion in V8 (CVE-2026-103625). All seven vulnerabilities are described by the vendor as allowing a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page.

Technical cause

Six of the seven vulnerabilities (CVE-2026-102323, CVE-2026-102328, CVE-2026-102299, CVE-2026-102321, CVE-2026-102326, and CVE-2026-103625) are classified as type confusion (CWE-843) in the V8 JavaScript engine, Chrome's component for executing JavaScript. Type confusion occurs when code treats a piece of memory as a different data type than it actually is, which can lead to memory corruption. The seventh, CVE-2026-103622, is a use-after-free (CWE-416) in Chrome's SVG rendering code, where memory that has already been freed is accessed again, also potentially leading to memory corruption and code execution.

Why it matters

Each of the seven vulnerabilities carries a CVSS base score of 8.8 (CVSS:3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), reflecting network-exploitable, low-complexity attacks with high impact on confidentiality, integrity, and availability. Exploitation requires no privileges but does require user interaction, such as visiting a malicious or compromised web page. Successful exploitation could allow an attacker to execute arbitrary code, though contained within Chrome's sandbox. Chaining such a flaw with a separate sandbox escape could result in broader system compromise, which is a known pattern for browser exploit chains.

Who is affected

Any user or organization running Google Chrome on desktop prior to the fixed versions is affected. Given Chrome's extremely large install base, this impacts a broad range of consumer and enterprise users across platforms where the Stable Channel update applies.

Affected and fixed versions

Google Chrome versions prior to 154.0.8037.92 are affected by CVE-2026-102323, CVE-2026-102328, CVE-2026-102299, CVE-2026-102321, and CVE-2026-102326, all fixed in version 154.0.8037.92. Google Chrome versions prior to 154.0.8037.97 are affected by CVE-2026-103622 and CVE-2026-103625, both fixed in version 154.0.8037.97. The fact package does not specify a lower bound for affected version ranges.

Fixes and mitigation

Google has released fixes for all seven vulnerabilities through the Chrome Stable Channel. Updating to version 154.0.8037.92 addresses the five V8 type confusion issues disclosed on September 29, 2026. Updating to version 154.0.8037.97 addresses the additional SVG use-after-free and V8 type confusion issues disclosed on October 2, 2026. No workarounds other than updating are described in the available facts.

Recommended action

Update Google Chrome to at least version 154.0.8037.97, which includes the fixes for all seven vulnerabilities described in this briefing. Chrome typically updates automatically, but administrators and users should manually verify the installed version via the browser's About page and restart the browser to apply the update. Organizations managing Chrome deployments via policy should confirm the update has propagated across all managed devices.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Why this score

All seven vulnerabilities share a PatchWire score of 5.9, driven primarily by a CVSS base score of 8.8 (contributing 4.84 points), reflecting network-based attacks requiring no privileges but some user interaction, with high impact on confidentiality, integrity, and availability. Additional contributions come from the unauthenticated remote attack vector (0.6 points) and Chrome's very large install base as a product popularity factor (0.5 points). None of the vulnerabilities are flagged as known exploited, associated with ransomware, or having a public exploit, and no EPSS score was available, which keeps the overall score moderate despite the high CVSS base rating.

Affected versions

≥ 154.0.8037.97
patched
≥ 154.0.8037.97
patched
≥ 154.0.8037.92
patched
≥ 154.0.8037.92
patched
≥ 154.0.8037.92
patched
≥ 154.0.8037.92
patched
≥ 154.0.8037.92
patched

Reported fixes

Google has released fixes for all seven vulnerabilities through the Chrome Stable Channel. Updating to version 154.0.8037.92 addresses the five V8 type confusion issues disclosed on September 29, 2026. Updating to version 154.0.8037.97 addresses the additional SVG use-after-free and V8 type confusion issues disclosed on October 2, 2026. No workarounds other than updating are described in the available facts.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome: Seven High-Severity Vulnerabilities Fixed in Two Stable Channel Updates
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email