GOOGLE has released Chrome 154 to the stable channel for Windows, Mac and Linux, fixing 108 security vulnerabilities across several browser components. The issues include memory-safety flaws such as buffer overflows, use-after-free vulnerabilities and out-of-bounds writes. Among the flaws highlighted are CVE-2026-95350, a critical buffer overflow in ANGLE; CVE-2026-95357, a critical out-of-bounds write in the GPU component; and CVE-2026-95339, a critical use-after-free issue in ServiceWorker.
The article says that exploitation could allow arbitrary code execution or cause the browser to crash, potentially after a user visits a specially crafted website. However, Google has not confirmed active exploitation of these specific vulnerabilities and says there are no public proof-of-concept exploits currently available. Google is restricting detailed bug information until most users have installed the update.
Users running versions before Chrome 154 are affected. Google is rolling out version 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and Mac. Users should open Chrome’s “About Chrome” page, allow the update to install and restart the browser.