GOOGLE has released Chrome 154.0.8037.97 (and 154.0.8037.98 on the Stable channel) to address a raft of 11 security bugs, led by a critical WebGL flaw that could allow remote code execution outside the browser sandbox. The bug, CVE-2026-103628, is an out-of-bounds write in WebGL that can be triggered by loading a crafted page, potentially giving an attacker control over the device without needing another bug to escape the sandbox. The update affects all Chrome desktop builds prior to 154.0.8037.97 on Windows, macOS and Linux.
The vulnerability roundup lists two other high-severity issues and eight unrated bugs. High-severity flaws include use-after-free and memory-related problems across components such as FedCM, Contextual Tasks, SVG, and MediaStream, plus a WebRTC buffer overflow tracked as CVE-2026-103631. Other notable CVEs include CVE-2026-103625, CVE-2026-103622 and CVE-2026-103626, with varying statuses of exploitation and analysis.
Google states that none of these bugs have been exploited in the wild and no public PoCs have been confirmed, though the firm and researchers credited with discovery collaborated on the fixes. Four of the 11 bugs were found by Google, with others reported by external researchers.
Users are urged to install the latest Chrome update promptly via Settings > About Chrome, then restart the browser to apply the fixes. The full release notes are linked in Google’s Stable Channel Update for Desktop post.