Vulnerabilities · 5h ago
Google released Chrome 154 to stable with 108 security fixes, including 11 critical and 25 high-severity flaws. Google and CSIRT Italia said the update covers Windows, macOS, and Linux builds, with no report of active exploitation.
Many of the critical bugs are memory-safety problems in core browser paths such as ANGLE, WebGL, GPU, ServiceWorker, and Fullscreen, including buffer overflows, out-of-bounds writes, and use-after-free defects. That means the browser itself had enough fault lines that a delayed update leaves a large mix of code paths exposed, even though this is routine patching rather than incident response.
For teams that run Chrome across managed fleets, the exposure is the normal browser maintenance window: systems that sit on older builds keep carrying the fixed flaws until the next update cycle lands.
2 sources covering this story
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox.
Risolte vulnerabilità in Google Chrome
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 32 nuove vulnerabilità di sicurezza, di cui 6 con gravità “critica” e 11 con gravità “alta”.
Risolte vulnerabilità in Google Chrome
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 108 nuove vulnerabilità di sicurezza, di cui 11 con gravità “critica” e 25 con gravità “alta”.
Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.
Part of the PlainSec briefing for 2026-09-30