Chrome users have a long list of reasons to hit “Relaunch” this week, and security is the biggest one.
Google has released Chrome 154 for Windows, Mac and Linux, packing fixes for 108 security vulnerabilities, including 11 rated critical. The stable-channel update began rolling out Tuesday and is expected to reach users over the coming days and weeks, according to Google’s Chrome Releases blog.
The affected desktop versions are Chrome 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and Mac.
According to Google’s release notes, the fixes span several browser components, with graphics and memory-safety bugs among the critical issues. Critical vulnerabilities include buffer overflows in ANGLE, out-of-bounds writes in the GPU component and WebGL, and use-after-free flaws affecting areas such as ServiceWorker and Fullscreen.
Graphics bugs deserve attention
One of the more notable vulnerabilities is CVE-2026-95350, a critical buffer overflow in ANGLE, Chrome’s graphics-translation layer. Google awarded a $5,000 bounty to researchers from STAR Labs SG for reporting it. A specially crafted webpage could potentially trigger the flaw, creating memory-safety problems that could result in a browser crash or potentially allow code execution.
Another critical ANGLE flaw, CVE-2026-95281, also involves a buffer overflow. Chrome also fixes CVE-2026-95357, a critical out-of-bounds write in its GPU component.
The update contains 25 high-severity vulnerabilities in addition to the 11 critical bugs. Google credited both external researchers and its own teams for vulnerabilities listed in the release.
Chrome gets an Android update, too
Google also released Chrome 154.0.8037.57 for Android. It says Android releases contain the same security fixes as their corresponding desktop releases unless otherwise noted. Chrome for iOS separately received version 154.0.8037.55.
What users should do now
Chrome normally downloads updates in the background, but a pending update takes effect only after users relaunch the browser.
To check manually, open Chrome's Help > About Google Chrome or Settings > About Google Chrome. Chrome will check for an available update and prompt users to relaunch. Linux users may need to use their system's update manager.
The sheer number of fixes is less important than where some of them sit. Chrome handles untrusted web content every day, while components such as ANGLE, WebGL, GPU processing and V8 sit close to sensitive browser operations. A flaw in one of these areas can turn an ordinary webpage into a potential attack surface.
For IT teams, the practical takeaway is to check which managed browsers have received Chrome 154 and prompt users to relaunch wherever an update is pending. At the same time, Google is restricting detailed bug information until more users receive the patches, limiting what researchers and attackers can learn before broader deployment.
Read more: Browser patching is one part of protecting company systems; a Google Gemini security test that reached three real companies shows why credentials and testing boundaries need attention, too.





