Chrome 154 Patches 108 Vulnerabilities
Chrome 154 update addresses 108 vulnerabilities, including 11 critical bugs.
Summary
Google has released Chrome 154, patching 108 vulnerabilities, with 11 classified as critical. These critical flaws include memory safety and corruption issues like buffer overflows and use-after-free bugs. While no exploitation in the wild has been reported, users are strongly advised to update promptly.
Full text
Google on Tuesday announced the release of Chrome 154 to the stable channel with patches for 108 vulnerabilities, including 11 critical-severity bugs. The critical security defects include buffer overflows (three in ANGLE and one in WebGL), out-of-bounds writes (two in GPU and one in WebGL), and use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter. Nine of the critical issues were reported by external researchers. In total, 32 of the newly patched flaws were reported externally, while the rest were discovered by Google. Google says it handed out $18,000 in bug bounty rewards to the reporting researchers, but the final amount could be much higher, as the company has yet to determine the amounts to be paid for most of the externally reported bugs. Twenty-five of the remaining vulnerabilities are high-severity bugs, including a dozen use-after-free defects and multiple type confusion, uninitialized resource, and buffer overflow issues. High-severity missing authorization, UI misinterpretation, incorrect authorization, improper output encoding, race condition, and out-of-bounds write flaws were also resolved.Advertisement. Scroll to continue reading. The remaining security holes are medium- and low-severity weaknesses related to authorization, input validation, UI misrepresentation, memory corruption, information leak, and memory safety. Google makes no mention of any of these vulnerabilities being exploited in the wild, but users are advised to update their browsers as soon as possible. The latest Chrome iteration is now rolling out as versions 154.0.8037.57/.58 for Windows and macOS, and as version 154.0.8037.57 for Linux. Related: Chrome, Firefox Updates Patch 115 Vulnerabilities Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day Related: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day Related: Check Point Patches Exploited Management Server Zero-Day Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire BigCommerce Data Stolen via Ribon Apps HackRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersMalicious B-tree NPM Package Accumulates Millions of DownloadsWordPress Patches ‘Click2Shell’ VulnerabilityFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerRatHat Android Trojan Uses AI for AutomationCrowdSec Confirms Source Code Stolen in Supply Chain AttackOrganizations Warned of 3 Exploited Linux Kernel Vulnerabilities Latest News Adobe Patches Critical Flaws in Connect, AEM FormsAI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftA Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at RiskOuterlimit Raises $16 Million to Stop Rogue AI Agents From Causing HarmArista Urges Immediate Patching of Exploited VCO Zero-DayCritical F5 BIG-IP Vulnerability Exploited as Zero-DayShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportCheck Point Patches Exploited Management Server Zero-Day Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email