Google Chrome 154 Fixes 108 Security Flaws: What IT Teams Should Check

Google chrome app displayed on a smartphone screen

Google pushes Chrome 154 update to fix 108 security flaws. Image: Zulfugar Karimov/Unsplash

Google Chrome 154 fixes 108 security flaws, including 11 critical bugs. Check affected versions and learn how IT teams can ensure the update takes effect.

Sep 25, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Chrome users have a long list of reasons to hit “Relaunch” this week, and security is the biggest one.

Google has released Chrome 154 for Windows, Mac and Linux, packing fixes for 108 security vulnerabilities, including 11 rated critical. The stable-channel update began rolling out Tuesday and is expected to reach users over the coming days and weeks, according to Google’s Chrome Releases blog.

The affected desktop versions are Chrome 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and Mac.

According to Google’s release notes, the fixes span several browser components, with graphics and memory-safety bugs among the critical issues. Critical vulnerabilities include buffer overflows in ANGLE, out-of-bounds writes in the GPU component and WebGL, and use-after-free flaws affecting areas such as ServiceWorker and Fullscreen.

Graphics bugs deserve attention

One of the more notable vulnerabilities is CVE-2026-95350, a critical buffer overflow in ANGLE, Chrome’s graphics-translation layer. Google awarded a $5,000 bounty to researchers from STAR Labs SG for reporting it. A specially crafted webpage could potentially trigger the flaw, creating memory-safety problems that could result in a browser crash or potentially allow code execution.

Another critical ANGLE flaw, CVE-2026-95281, also involves a buffer overflow. Chrome also fixes CVE-2026-95357, a critical out-of-bounds write in its GPU component. 

The update contains 25 high-severity vulnerabilities in addition to the 11 critical bugs. Google credited both external researchers and its own teams for vulnerabilities listed in the release.

Chrome gets an Android update, too

Google also released Chrome 154.0.8037.57 for Android. It says Android releases contain the same security fixes as their corresponding desktop releases unless otherwise noted. Chrome for iOS separately received version 154.0.8037.55.

What users should do now

Chrome normally downloads updates in the background, but a pending update takes effect only after users relaunch the browser.

To check manually, open Chrome's Help > About Google Chrome or Settings > About Google Chrome. Chrome will check for an available update and prompt users to relaunch. Linux users may need to use their system's update manager.

The sheer number of fixes is less important than where some of them sit. Chrome handles untrusted web content every day, while components such as ANGLE, WebGL, GPU processing and V8 sit close to sensitive browser operations. A flaw in one of these areas can turn an ordinary webpage into a potential attack surface.

Advertisement

For IT teams, the practical takeaway is to check which managed browsers have received Chrome 154 and prompt users to relaunch wherever an update is pending. At the same time, Google is restricting detailed bug information until more users receive the patches, limiting what researchers and attackers can learn before broader deployment.

Read more: Browser patching is one part of protecting company systems; a Google Gemini security test that reached three real companies shows why credentials and testing boundaries need attention, too.

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.