

108 Vulnerabilities Fixed: Chrome 154 addresses 11 Critical, 25 High, 47 Medium, and 25 Low-severity security issues.
Major Components Affected: Critical flaws impact ANGLE, GPU, WebGL, ServiceWorker, Fullscreen, WindowDialog, and AdFilter.
Updating is Important: No known attacks target these flaws currently, but patched vulnerabilities can become easier to exploit after disclosure.
Chrome 154 brings a major security repair to Google’s browser. The Stable Channel release fixes 108 security vulnerabilities, with 11 rated Critical and 25 rated High. Google released Chrome 154 for Windows, Mac, and Linux on September 22, 2026, with a gradual rollout across the next several days and weeks. The desktop builds are 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and Mac.
The 108 flaws cover a wide range of security problems. The full set contains 11 Critical, 25 High, 47 Medium, and 25 Low severity issues. Memory safety problems form a major part of the release, with flaws across Chrome components such as ANGLE, GPU, WebGL, ServiceWorker, Fullscreen, WindowDialog, and AdFilter.
Google lists several serious memory corruption flaws among the Critical issues. CVE-2026-95350 affects ANGLE with a buffer overflow, while CVE-2026-95357 affects the GPU with an out-of-bounds write. CVE-2026-95339 affects ServiceWorker with a use-after-free flaw. Other Critical bugs affect Fullscreen, WebGL, WindowDialog, and AdFilter. These flaw types can create serious security risks when hostile web content reaches a vulnerable browser component.
ANGLE, a graphics layer used by Chrome, has several Critical fixes in this release. Google lists three Critical buffer overflow flaws in ANGLE. Chrome also fixes Critical out-of-bounds write flaws in GPU and WebGL. Such defects matter since browsers process complex web content through graphics and other low-level components.
The release also fixes use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter. A use-after-free flaw can cause software to access memory after that memory no longer belongs to the expected object. Attackers can sometimes turn such memory errors into crashes or more serious security problems, although the public information does not show a confirmed attack path for every Chrome 154 flaw.
Also Read - How to Download Your Google Account Data
Google found 76 of the 108 vulnerabilities, while external security researchers reported the other 32. Nine of the 11 Critical flaws came from external researchers. Google had awarded $18,000 in bug bounty payments at the time of the release, while final rewards for several reports remained undecided.
The reward figures show how much security research contributes to Chrome’s defense. Researchers from outside Google found serious flaws across graphics, browser services, and other parts of the browser. Google also keeps some technical details restricted until a large share of Chrome users receives the fixes. That approach can limit the amount of information available to attackers before the patch reaches a broad audience.
Current reports do not show known exploitation of the 108 Chrome 154 vulnerabilities in real-world attacks. SecurityWeek and PCWorld both reported no known active attacks tied to this specific set of flaws at the time of publication. That status can change after researchers and attackers study the fixes and the affected code.
The lack of known attacks does not make an old Chrome version safe. Once a browser patch becomes public, security researchers can compare the repaired code with older versions and identify the cause of a flaw. That process can reveal useful details about possible attack methods. A browser patch therefore matters even before a public exploit appears.
Google also released Chrome 154.0.8037.57 for Android on September 22. Google says the Android release contains the same security fixes as the related desktop release unless a release note says otherwise. Google planned a gradual Google Play rollout over the following days.
PCWorld also reports Chrome 154.0.8037.55 for iOS. The Android release carries the same core security fixes as the desktop versions, while Chrome releases can use different version numbers across platforms.
Why this Matters
Chrome 154 matters for browser security as it fixes 108 vulnerabilities, including 11 Critical and 25 High-severity flaws. Several affect core Chrome components such as GPU, WebGL, ANGLE, and ServiceWorker. The update reduces exposure to known security weaknesses and gives users stronger protection against potential attacks through harmful web content.
Chrome normally checks for updates on its own. A manual check takes only a few steps. Open the Chrome menu, select Help, then choose About Google Chrome. Chrome can also reach the update page through chrome://settings/help. After Chrome installs the latest version, a browser restart completes the process.
Chrome 154 matters less for a new feature headline than for the size and severity of its security repair. 108 vulnerabilities, 11 Critical flaws, 25 High-severity flaws, and several serious memory safety defects make this release a key security update. Google’s current data shows no known attacks against these specific flaws, yet the scale of the patch gives Chrome users a clear reason to move to the latest stable build.
1. What does Chrome 154 fix?
Chrome 154 fixes 108 security vulnerabilities across multiple browser components.
2. How many Critical vulnerabilities were fixed?
The release addresses 11 Critical-severity vulnerabilities.
3. Are these Chrome 154 vulnerabilities being actively exploited?
There were no known real-world attacks targeting these specific vulnerabilities at the time of the release.
4. How can I update Chrome?
Go to Chrome → Help → About Google Chrome. Chrome will check for and install available updates.
5. Why should I update if there are no known attacks?
Publicly disclosed fixes can help researchers identify vulnerabilities and potentially develop exploits, making timely updates an important security measure.