www.malwarebytes.com 24 Sept 2026, 11:06 UTC

Google Patches Critical Chrome Flaws That Could Enable Code Execution

Google Patches Critical Chrome Flaws That Could Enable Code Execution
CyberSIXT Evidence Panel Source marked as original reporting

GOOGLE has released a Chrome Stable Channel update for desktop, bringing the browser to version **154.0.8037.57 on Linux** and **154.0.8037.57/.58 on Windows and Mac**. Released on 22 September 2026, it addresses **108 security issues**, including **11 rated Critical**, with the update rolling out over the following days and weeks.

The article highlights three vulnerabilities. **CVE-2026-95350** is a Critical buffer overflow in ANGLE, Chrome’s graphics-translation layer. A specially crafted webpage could potentially trigger memory-safety problems, including a crash or possible code execution. **CVE-2026-95281** is another Critical ANGLE buffer overflow that a malicious webpage could potentially reach, although Google has not provided exploitation details. **CVE-2026-95357** is an out-of-bounds write in Chrome’s GPU component. The report describes these as potential impacts and does not confirm exploitation.

Google also released **Chrome 155.0.8059.16 for Android** on 23 September 2026 to a small percentage of users, with stability and performance improvements. Chrome 155 is additionally available through the Beta channel. Desktop users can wait for automatic updating or open **About Google Chrome** in the settings or Help menu, then select **Relaunch** when prompted.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline