Medium · 4.8 Browsers CVE-2026-95298 CVE-2026-95297 CVE-2026-95303 CVE-2026-95382
Google Chrome Stable Update Fixes Eight Vulnerabilities, Including a High-Severity Use-After-Free
Google has released a Chrome Stable channel update addressing eight vulnerabilities, including one high-severity use-after-free flaw and seven medium-severity issues affecting browser components such as Downloads, Network, Auth, and SmartCard. All are fixed in version 154.0.8037.57.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
AI summary
Google has published a Stable Channel update for Chrome on desktop, resolving eight distinct vulnerabilities identified by Chromium's security team. The update, version 154.0.8037.57, addresses one high-severity use-after-free vulnerability and seven medium-severity issues spanning multiple browser components, including Downloads, Network, Auth, SmartCard, Core, Transactions Platform, and Contextual Tasks. None of these vulnerabilities are currently known to be exploited in the wild, and no public exploit code has been reported.
Overview of the Fixed Vulnerabilities
Google released a Chrome Stable update fixing eight vulnerabilities disclosed under CVE-2026-95298, CVE-2026-95297, CVE-2026-95303, CVE-2026-95382, CVE-2026-95366, CVE-2026-95374, CVE-2026-95336, and CVE-2026-95330. The most severe, CVE-2026-95298, is a use-after-free in the Browser component with a Chromium-assessed severity of High, which could allow a local attacker to potentially execute arbitrary code outside the sandbox via UI interaction. The remaining seven vulnerabilities are rated Medium severity by Chromium and involve issues such as missing authorization, incomplete cleanup, improper input validation, use of a released resource, incorrect authorization, information leak, and improper state validation, affecting components including Contextual Tasks, SmartCard, Auth, Core, Network, Transactions Platform, and Downloads.
Technical Root Causes
The vulnerabilities stem from distinct underlying weaknesses across different Chrome components. CVE-2026-95298 (CWE-416, Use After Free) affects the Browser component. CVE-2026-95297 (CWE-862, Missing Authorization) affects Contextual Tasks. CVE-2026-95303 (CWE-459, Incomplete Cleanup) affects SmartCard. CVE-2026-95382 (CWE-20, Improper Input Validation) affects Auth. CVE-2026-95366 (CWE-672, Use of Released Resource) affects Core. CVE-2026-95374 (CWE-863, Incorrect Authorization) affects Network. CVE-2026-95336 (CWE-200, Information Leak) affects Transactions Platform. CVE-2026-95330 (CWE-754, Improper State Validation) affects Downloads. Each vulnerability requires a crafted HTML page or, in the case of CVE-2026-95298, local UI interaction, to be triggered.
Why This Matters
The high-severity use-after-free (CVE-2026-95298) is notable because it could allow code execution outside Chrome's sandbox, which is a significant containment boundary. While it requires local access and user interaction, successful exploitation would undermine one of Chrome's core security protections. The medium-severity issues, while less critical individually, involve bypasses of web origin policy and system access restrictions, as well as information disclosure, which could be leveraged in combination with other attack techniques, particularly those relying on social engineering or a crafted HTML page.
Who Is Affected
All users running Google Chrome on desktop prior to version 154.0.8037.57 are affected. This includes individual users and organizations deploying Chrome across their environments.
Affected and Fixed Versions
Google Chrome versions prior to 154.0.8037.57 are affected by these vulnerabilities. The fix for all eight CVEs is included in version 154.0.8037.57.
Fixes and Mitigation
Google has released version 154.0.8037.57 of the Stable channel for desktop, which resolves all eight vulnerabilities described in this briefing. Chrome's automatic update mechanism will typically apply this update, though users and administrators should verify their installed version.
Recommended Action
Users and administrators should ensure Google Chrome is updated to version 154.0.8037.57 or later as soon as possible. Check the current version via Chrome's About page (chrome://settings/help), which will also trigger an update check if one is pending. Organizations managing Chrome deployments at scale should verify that automated update policies are functioning correctly and push the update where necessary.
PatchBriefing score
4.8 / 10 · Medium
Official CVSS: 7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Why this score
The overall severity scores for these vulnerabilities range from 4.7 to 4.8 on the Patchwire scale. CVE-2026-95298 has a CVSS base score of 7.8 (High), driven by its potential for arbitrary code execution outside the sandbox, though it requires local access and user interaction, which limits its exploitability. The remaining seven vulnerabilities each carry a CVSS base score of 6.5 (Medium), reflecting network-exploitable issues that require user interaction via a crafted HTML page. None of the vulnerabilities are known to be exploited in the wild, and no public exploit code has been reported, which keeps the composite Patchwire scores in the moderate range despite the underlying CVSS severity of the lead vulnerability.
Affected versions
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
- ≥ 154.0.8037.57
- patched
Reported fixes
Google has released version 154.0.8037.57 of the Stable channel for desktop, which resolves all eight vulnerabilities described in this briefing. Chrome's automatic update mechanism will typically apply this update, though users and administrators should verify their installed version.
How this was built
9 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email