T
Threats
Google Chrome Multiple Critical Vulnerabilities
Overview
CVEs: CVE-2026-95313, CVE-2026-95329, CVE-2026-95339, CVE-2026-95349, CVE-2026-95350, CVE-2026-95356, CVE-2026-95357, CVE-2026-95277, CVE-2026-95283, CVE-2026-95299, CVE-2026-95318, CVE-2026-95311, CVE-2026-95325, CVE-2026-95331, CVE-2026-95347
Overall severity: Critical
Date: 1 October 2026
Google has released fixes for 15 vulnerabilities affecting Chrome across desktop and Android-related components, including use-after-free flaws, buffer overflows and out-of-bounds writes in WebGL, ANGLE, GPU and other components.
Several vulnerabilities could allow a remote attacker to execute code outside Chrome’s sandbox when a user processes crafted web content. Organisations should update Chrome to the latest stable release across all managed devices and verify the installed version.
Affected Versions
Affected: The project intake states versions prior to Chrome 154.0.8037.57 are affected. Google’s 22 September 2026 desktop release lists Chrome 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and macOS as the stable update containing these security fixes.
Fixed: Upgrade to a current Chrome stable release at or above the applicable platform build. The exact Android fixed build and the platform-specific scope for each CVE were not confirmed in the accessible official release material.
Source: Google Chrome Stable Channel Update for Desktop, 22 September 2026
Vulnerability Breakdown
CVE-2026-95313 - Use after free in Fullscreen
CVSS: 9.6
Description: A use-after-free flaw in Chrome Fullscreen. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Remote attacker; victim processes a crafted HTML page.
CVE-2026-95329 - Out-of-bounds write in WebGL
CVSS: 9.6
Description: An out-of-bounds write in WebGL. The intake identifies Android and says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Android, remote attacker, and victim processes a crafted HTML page.
CVE-2026-95339 - Use after free in ServiceWorker
CVSS: 9.6
Description: A use-after-free flaw in ServiceWorker. The intake says a remote attacker could execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Remote attacker; victim processes a crafted HTML page.
CVE-2026-95349 - Buffer overflow in WebGL
CVSS: 9.6
Description: A WebGL buffer overflow. The intake identifies Android and says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Android, remote attacker, and victim processes a crafted HTML page.
CVE-2026-95350 - Buffer overflow in ANGLE
CVSS: 9.6
Description: A buffer overflow in ANGLE. The intake identifies Android and says a remote attacker could execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Android, remote attacker, and victim processes a crafted HTML page.
CVE-2026-95356 - Use after free in WindowDialog
CVSS: 9.6
Description: A use-after-free flaw in WindowDialog. The intake says a remote attacker leveraging social engineering could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Social engineering is required, followed by processing a crafted HTML page.
CVE-2026-95357 - Out-of-bounds write in GPU
CVSS: 9.6
Description: An out-of-bounds write in the GPU component. The intake identifies Android and says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Android, remote attacker, and victim processes a crafted HTML page.
CVE-2026-95277 - Use after free in Views
CVSS: 9.6
Description: A use-after-free flaw in Views. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Remote attacker; victim processes a crafted HTML page.
CVE-2026-95283 - Buffer overflow in Tint
CVSS: 9.6
Description: A buffer overflow in Tint. The intake identifies Android and says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Android, remote attacker, and victim processes a crafted HTML page.
CVE-2026-95299 - Use after free in GPU
CVSS: 9.6
Description: A use-after-free flaw in the GPU component. The intake says a remote attacker could execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Remote attacker; victim processes a crafted HTML page.
CVE-2026-95318 - Buffer overflow in Video
CVSS: 9.6
Description: A buffer overflow in Video. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Remote attacker; victim processes a crafted HTML page.
CVE-2026-95311 - Free of non-heap memory in Fonts
CVSS: 9.6
Description: The supplied description identifies a free-of-non-heap-memory flaw in Fonts. It says a remote attacker leveraging social engineering could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Social engineering is required, followed by processing a crafted HTML page.
CVE-2026-95325 - Use after free in ANGLE
CVSS: 9.6
Description: A use-after-free flaw in ANGLE. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Remote attacker; victim processes a crafted HTML page.
CVE-2026-95331 - Out-of-bounds write in ANGLE
CVSS: 9.6
Description: An out-of-bounds write in ANGLE. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: Remote attacker; victim processes a crafted HTML page.
CVE-2026-95347 - Use after free in Updater
CVSS: 9.6
Description: A use-after-free flaw in Updater. The intake identifies macOS and says a remote attacker could execute code outside the sandbox via crafted network traffic.
Impact: Potential arbitrary code execution outside Chrome’s sandbox.
Conditions: macOS and crafted network traffic.
Mitigation
Update Google Chrome to the latest stable version offered for each platform. Google’s 22 September desktop release includes fixes in Chrome 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and macOS.
Verify the installed version on managed devices and confirm Android devices receive the applicable stable update.
Restart Chrome after updating and confirm the update has completed.
Summary for IT Teams
Products: Google Chrome on desktop; Android-related components are identified in the intake for selected CVEs.
Threat Level: Critical overall. Google’s release notes classify the individual issues as Critical, High, or Medium. The project intake lists CVSS 9.6 for all 15, but that score was not confirmed in Google’s accessible release notes.
Action Required: Deploy the current Chrome stable update across managed endpoints and verify platform-specific versions, including Android.
Reference
Need Help?
Contact Secure ISS on 1300 769 460 or email us for assistance assessing Chrome exposure and coordinating updates.

