Chrome 154 patch addresses critical vulnerabilities, including graphics stack flaws

Google releases Chrome 154, a major security update fixing 108 vulnerabilities across multiple platforms, with a focus on graphics-related exploits and critical bugs that could enable malicious code execution.

Google has released Chrome 154, a security-focused update that closes 108 vulnerabilities across Windows, macOS and Linux, including 11 classed as critical. The scale of the patch makes it one of the larger recent Chrome security releases and underlines how often widely used browser code becomes the target of active research and exploitation attempts.

According to SecurityWeek, the most serious flaws are concentrated in Chrome’s graphics stack, notably ANGLE, WebGL and the GPU component. Those issues include buffer overflows, out-of-bounds writes and use-after-free bugs, all of which can, in the wrong circumstances, allow malicious code to run on a device after a user visits a booby-trapped page. Malwarebytes separately identified one of the bugs, CVE-2026-95350, as a buffer overflow in ANGLE that could be triggered by a specially crafted webpage.

Google said in its security bulletin that none of the 108 issues is known to be under active exploitation at present, but that does not reduce the urgency of installing the update. Chrome’s sandbox architecture still provides an important layer of containment, limiting the damage from many browser bugs by isolating websites from the broader system. Even so, vulnerabilities in rendering code and graphics handling remain particularly sensitive because they can sometimes be reached simply by loading content in the browser.

The patch is also significant because Chrome’s reach is so large. The browser accounts for a substantial share of the global market, which means a flaw in Chrome, or in Chromium-based browsers that share the same underlying codebase, can affect millions of users at once. SecurityWeek reported that external researchers disclosed nine of the critical issues and that Google issued bug bounty payments, with more awards still pending in some cases.

Users on desktop can check their version by opening Chrome’s menu, selecting Help and then About Google Chrome, where the browser should download the update automatically and ask for a restart. Google’s release notes indicate that Windows and macOS users should be on version 154.0.8037.57 or .58, while Linux users should have 154.0.8037.57. On Android, the rollout goes through the Google Play Store and may reach users more gradually, while iPhone users also received the fix this week.

The update arrives against a backdrop of frequent high-volume browser patching. Chrome has shipped similarly large security batches before, and Microsoft recently pushed out a Windows update that addressed close to 1,000 flaws in one release. Chrome 155 is expected in roughly two weeks, but the immediate priority is simpler: install the current fix and restart the browser.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.