Skip to content

Security2 publishers2 min readPublished

Chrome 154's 11 critical fixes: seven in webpage-reachable graphics code, four use-after-free bugs elsewhere

Google shipped 108 security fixes to the Chrome stable channel on September 22, eleven of them rated Critical and seven of those in graphics components a crafted page can drive. None were reported as exploited.

The Watch · Security desk

Illustration accompanying Chrome 154's 11 critical fixes: seven in webpage-reachable graphics code, four use-after-free bugs elsewhere

What happened

  • Google's September 22 Chrome stable channel update for desktop carries 108 security fixes, 11 of them rated Critical, as versions 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and Mac.
  • Malwarebytes says a crafted webpage could trigger CVE-2026-95350, a buffer overflow in Chrome's ANGLE graphics-translation layer, with outcomes from a browser crash to possible code execution.
  • A day later Google pushed Chrome 155.0.8059.16 to a small share of Android users as an Early Stable rollout, describing it as stability and performance improvements.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure An endpoint stays on the old build until the Chrome process actually restarts, so the long-running session belonging to the busiest user is the one still reachable from a web page.
  • decision Fleet owners choose between a forced relaunch inside business hours and the staged rollout, and the staged option has no fixed completion date to report to a risk owner.
  • constraint Reading this release CVE by CVE does not change the action available, because the only thing an admin can enforce is the version string and the only evidence of compliance is a restarted browser.

ANGLE is the layer that translates Chrome's graphics calls for the host system, and it holds three of the eleven Critical entries [5]. Malwarebytes flags a second of them, CVE-2026-95281, as the same buffer overflow class in the same component, reachable by a malicious webpage [12]. A third, CVE-2026-95357, is an out-of-bounds write in the GPU component, the part of Chrome that talks to the machine's graphics processor [13]. Sort the Critical list by component and seven of the eleven sit in graphics code: three ANGLE overflows, one in WebGL, two out-of-bounds writes in GPU, one more in WebGL [5][2]. The remaining four are use-after-free bugs [5].

Below the Critical tier sit 25 high-severity bugs, a dozen of them use-after-free, which leaves 72 of the 108 in the medium and low bands [8][1]. Google did not report any of the 108 as exploited in the wild, according to SecurityWeek, and told users to update as soon as possible [9].

The release rolls out over days and weeks rather than landing at once [4]. Malwarebytes notes two ways a machine falls behind anyway: a browser that is never closed, and an extension that blocks the update [16]. The manual path is About Google Chrome from the settings or Help menu, then Relaunch [17].

Thirty-two of the 108 came from external researchers, including nine of the eleven Critical bugs, so Google's own people found 76 [6][3]. Google says it has handed out $18,000 in bounties so far and has yet to set the amounts for most of the externally reported bugs [7]. Divided across the 32 external reports, the figure disclosed to date works out to roughly $560 each [4].

Android moved separately. On September 23, one day after the desktop release, Google pushed Chrome 155.0.8059.16 to a small share of Android users as an Early Stable rollout, and described the contents as stability and performance improvements [14][5]. Malwarebytes says it may not be on Google Play for everyone yet [14]. Chrome 155 is also in the Beta channel, which runs roughly four to six weeks ahead of Stable and is meant for testing [15].

What makes this a same-week action is the entry point: a page in a tab hitting graphics code in eleven bugs Google rated Critical [5][11].

What to watch

  • Whether any of the 11 Critical bugs turns up in exploitation reporting or on CISA's KEV list, which would move this from scheduled patching to incident work.
  • The final bounty total once Google sets amounts for the remaining externally reported bugs, against the $18,000 disclosed at release.
  • Whether Chrome 155 graduates from Early Stable on Android with its own security fix list, or stays a stability and performance release.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories