T

Threats

Google Chrome Multiple Critical Vulnerabilities

Overview

  • CVEs: CVE-2026-95313, CVE-2026-95329, CVE-2026-95339, CVE-2026-95349, CVE-2026-95350, CVE-2026-95356, CVE-2026-95357, CVE-2026-95277, CVE-2026-95283, CVE-2026-95299, CVE-2026-95318, CVE-2026-95311, CVE-2026-95325, CVE-2026-95331, CVE-2026-95347

  • Overall severity: Critical

  • Date: 1 October 2026

Google has released fixes for 15 vulnerabilities affecting Chrome across desktop and Android-related components, including use-after-free flaws, buffer overflows and out-of-bounds writes in WebGL, ANGLE, GPU and other components.

Several vulnerabilities could allow a remote attacker to execute code outside Chrome’s sandbox when a user processes crafted web content. Organisations should update Chrome to the latest stable release across all managed devices and verify the installed version.

Affected Versions

  • Affected: The project intake states versions prior to Chrome 154.0.8037.57 are affected. Google’s 22 September 2026 desktop release lists Chrome 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and macOS as the stable update containing these security fixes.

  • Fixed: Upgrade to a current Chrome stable release at or above the applicable platform build. The exact Android fixed build and the platform-specific scope for each CVE were not confirmed in the accessible official release material.

  • Source: Google Chrome Stable Channel Update for Desktop, 22 September 2026

Vulnerability Breakdown

CVE-2026-95313 - Use after free in Fullscreen

  • CVSS: 9.6

  • Description: A use-after-free flaw in Chrome Fullscreen. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Remote attacker; victim processes a crafted HTML page.

CVE-2026-95329 - Out-of-bounds write in WebGL

  • CVSS: 9.6

  • Description: An out-of-bounds write in WebGL. The intake identifies Android and says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Android, remote attacker, and victim processes a crafted HTML page.

CVE-2026-95339 - Use after free in ServiceWorker

  • CVSS: 9.6

  • Description: A use-after-free flaw in ServiceWorker. The intake says a remote attacker could execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Remote attacker; victim processes a crafted HTML page.

CVE-2026-95349 - Buffer overflow in WebGL

  • CVSS: 9.6

  • Description: A WebGL buffer overflow. The intake identifies Android and says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Android, remote attacker, and victim processes a crafted HTML page.

CVE-2026-95350 - Buffer overflow in ANGLE

  • CVSS: 9.6

  • Description: A buffer overflow in ANGLE. The intake identifies Android and says a remote attacker could execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Android, remote attacker, and victim processes a crafted HTML page.

CVE-2026-95356 - Use after free in WindowDialog

  • CVSS: 9.6

  • Description: A use-after-free flaw in WindowDialog. The intake says a remote attacker leveraging social engineering could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Social engineering is required, followed by processing a crafted HTML page.

CVE-2026-95357 - Out-of-bounds write in GPU

  • CVSS: 9.6

  • Description: An out-of-bounds write in the GPU component. The intake identifies Android and says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Android, remote attacker, and victim processes a crafted HTML page.

CVE-2026-95277 - Use after free in Views

  • CVSS: 9.6

  • Description: A use-after-free flaw in Views. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Remote attacker; victim processes a crafted HTML page.

CVE-2026-95283 - Buffer overflow in Tint

  • CVSS: 9.6

  • Description: A buffer overflow in Tint. The intake identifies Android and says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Android, remote attacker, and victim processes a crafted HTML page.

CVE-2026-95299 - Use after free in GPU

  • CVSS: 9.6

  • Description: A use-after-free flaw in the GPU component. The intake says a remote attacker could execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Remote attacker; victim processes a crafted HTML page.

CVE-2026-95318 - Buffer overflow in Video

  • CVSS: 9.6

  • Description: A buffer overflow in Video. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Remote attacker; victim processes a crafted HTML page.

CVE-2026-95311 - Free of non-heap memory in Fonts

  • CVSS: 9.6

  • Description: The supplied description identifies a free-of-non-heap-memory flaw in Fonts. It says a remote attacker leveraging social engineering could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Social engineering is required, followed by processing a crafted HTML page.

CVE-2026-95325 - Use after free in ANGLE

  • CVSS: 9.6

  • Description: A use-after-free flaw in ANGLE. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Remote attacker; victim processes a crafted HTML page.

CVE-2026-95331 - Out-of-bounds write in ANGLE

  • CVSS: 9.6

  • Description: An out-of-bounds write in ANGLE. The intake says a remote attacker could potentially execute code outside the sandbox through a crafted HTML page.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: Remote attacker; victim processes a crafted HTML page.

CVE-2026-95347 - Use after free in Updater

  • CVSS: 9.6

  • Description: A use-after-free flaw in Updater. The intake identifies macOS and says a remote attacker could execute code outside the sandbox via crafted network traffic.

  • Impact: Potential arbitrary code execution outside Chrome’s sandbox.

  • Conditions: macOS and crafted network traffic.

Mitigation

  • Update Google Chrome to the latest stable version offered for each platform. Google’s 22 September desktop release includes fixes in Chrome 154.0.8037.57 for Linux and 154.0.8037.57/.58 for Windows and macOS.

  • Verify the installed version on managed devices and confirm Android devices receive the applicable stable update.

  • Restart Chrome after updating and confirm the update has completed.

Summary for IT Teams

  • Products: Google Chrome on desktop; Android-related components are identified in the intake for selected CVEs.

  • Threat Level: Critical overall. Google’s release notes classify the individual issues as Critical, High, or Medium. The project intake lists CVSS 9.6 for all 15, but that score was not confirmed in Google’s accessible release notes.

  • Action Required: Deploy the current Chrome stable update across managed endpoints and verify platform-specific versions, including Android.

Reference

Need Help?

Contact Secure ISS on 1300 769 460 or email us for assistance assessing Chrome exposure and coordinating updates.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.