Medium · 4.7 Browsers CVE-2026-103627 CVE-2026-102329 CVE-2026-102320 CVE-2026-102310
Google Chrome Patches Seven Vulnerabilities, Including Sandbox-Escape-Style Origin Bypasses
Google has fixed seven vulnerabilities in Chrome, including origin policy bypasses, a WebUI cross-site scripting issue, an SVG information leak, and two UI spoofing flaws. Updates to 154.0.8037.92 and 154.0.8037.97 are available.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 4d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
AI summary
Google has released two stable channel updates for Chrome on desktop that together address seven distinct vulnerabilities. The issues range from web origin policy bypasses and a cross-site scripting flaw in Chrome's internal WebUI pages, to an information leak via SVG handling and UI spoofing issues affecting the tab strip and the sign-in flow on iOS. None of the issues are reported as actively exploited, and no public exploit code has been disclosed. Fixes are available in Chrome 154.0.8037.92 and, for the SVG issue, in the later 154.0.8037.97 release.
What happened
Google published two Chrome Stable Channel updates that collectively fix seven security vulnerabilities. The first update (version 154.0.8037.92) addresses six issues: an incorrect authorization bug in SiteIsolation (CVE-2026-102330), a missing authorization bug in Payments (CVE-2026-102310), a missing authorization bug in CORS (CVE-2026-102320), a cross-site scripting flaw in WebUI (CVE-2026-102329), a UI misrepresentation issue in TabStrip (CVE-2026-102314), and a UI misrepresentation issue affecting SignIn on Chrome for iOS (CVE-2026-102305). A second update (version 154.0.8037.97) separately fixes an information leak in SVG handling (CVE-2026-103627).
Technical cause
The vulnerabilities stem from several distinct root causes. CVE-2026-102330 (SiteIsolation) and CVE-2026-102320 (CORS) involve missing or incorrect authorization checks (CWE-863 and CWE-862) that could allow a remote attacker who has already compromised a renderer process to bypass web origin policy using a crafted HTML page. CVE-2026-102310 (Payments) is a similar missing authorization issue (CWE-862) with the same origin-bypass impact. CVE-2026-102329 is a cross-site scripting vulnerability (CWE-79) in Chrome's WebUI component that could let an attacker bypass origin policy to inject content into a privileged internal page. CVE-2026-103627 is an information leak (CWE-200) in SVG handling that could expose sensitive information via a crafted HTML page. CVE-2026-102314 and CVE-2026-102305 are both UI misrepresentation issues (CWE-451) — one in the TabStrip component and one in the SignIn flow specific to Chrome on iOS — that could let an attacker spoof UI elements via a crafted HTML page.
Why it matters
Several of these flaws weaken Chrome's origin isolation model, which is the core mechanism that keeps content from different websites separated. The origin-bypass issues in SiteIsolation, CORS, and Payments require an attacker to have already compromised a renderer process, which raises the bar for exploitation but means these bugs could be chained with other vulnerabilities for greater impact. The WebUI cross-site scripting issue is notable because it affects privileged internal Chrome pages, carrying Chromium's 'High' severity rating. The SVG information leak could expose sensitive data to a remote attacker without requiring a prior compromise. The two UI spoofing issues could be used to mislead users about what they are interacting with, which is a common building block in phishing-style attacks.
Who is affected
All users running Google Chrome on desktop prior to version 154.0.8037.92 are affected by six of the seven issues. The SVG information leak (CVE-2026-103627) affects Chrome versions prior to 154.0.8037.97. The UI spoofing issue described in CVE-2026-102305 specifically affects Chrome on iOS.
Affected versions
Chrome prior to 154.0.8037.92 is affected by CVE-2026-102330, CVE-2026-102310, CVE-2026-102320, CVE-2026-102329, CVE-2026-102314, and CVE-2026-102305. Chrome prior to 154.0.8037.97 is affected by CVE-2026-103627. No specific earliest-affected version numbers were provided in the source material.
Fixes and mitigation
Google has released fixes for all seven vulnerabilities. Six issues are resolved in Chrome 154.0.8037.92, and the SVG information leak is resolved in the subsequent Chrome 154.0.8037.97 release. These fixes are distributed through Chrome's standard Stable Channel update mechanism.
Recommended action
Update Google Chrome to version 154.0.8037.97 or later, which includes the fixes from both stable channel releases described here. Chrome typically updates automatically, but users and administrators should verify the installed version via Chrome's About page and restart the browser to apply the update if it has not already been applied.
PatchBriefing score
4.7 / 10 · Medium
Official CVSS: 6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Why this score
The Patchwire scores for these issues range from 4.1 to 4.7, reflecting moderate severity. These scores are driven primarily by CVSS base scores between 5.4 and 6.5, combined with a small contribution for remote, unauthenticated exploitability and Chrome's broad user base. None of the issues are known to be exploited in the wild, and no public exploit code has been reported, which keeps the overall scores in the moderate range despite the sensitivity of the affected components.
Affected versions
- ≥ 154.0.8037.97
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
- ≥ 154.0.8037.92
- patched
Reported fixes
Google has released fixes for all seven vulnerabilities. Six issues are resolved in Chrome 154.0.8037.92, and the SVG information leak is resolved in the subsequent Chrome 154.0.8037.97 release. These fixes are distributed through Chrome's standard Stable Channel update mechanism.
How this was built
9 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email