VYPR
Vypr IntelligenceAI-generatedOct 2, 2026· 11 CVEs

Chrome 154.0.8037.97: Eleven Vulnerabilities Including Critical RCE Flaws Patched Together

Google Chrome 154.0.8037.97 addresses eleven vulnerabilities, including critical and high-severity flaws in WebRTC, WebGL, and V8, patched on October 2, 2026.

Key findings

  • Google Chrome 154.0.8037.97 patches eleven vulnerabilities disclosed on October 2, 2026.
  • The batch includes one critical and multiple high-severity flaws, with several allowing remote code execution.
  • Vulnerabilities affect key components such as WebRTC, WebGL, V8, and FedCM.
  • Flaws range from buffer overflows and use-after-free bugs to integer overflows and incorrect authorization.
  • All disclosed vulnerabilities are fixed in Chrome version 154.0.8037.97; users should update immediately.

On October 2, 2026, Google released Chrome version 154.0.8037.97, patching a batch of eleven vulnerabilities that were disclosed on the same day. These vulnerabilities span various components of the browser, including WebRTC, FedCM, Skia, WebGL, FileSystem, V8, Contextual Tasks, MediaStream, and Compositing. The disclosures include one critical vulnerability and several high-severity flaws, posing a significant risk to users if left unpatched.

Several vulnerabilities allow for remote code execution. CVE-2026-103631, a buffer overflow in WebRTC, and CVE-2026-103630, a use-after-free in FedCM, both permit remote attackers to execute arbitrary code within the sandbox via a crafted HTML page. Similarly, CVE-2026-103625, a type confusion in the V8 JavaScript engine, and CVE-2026-103622, a use-after-free in SVG, also enable arbitrary code execution inside the sandbox. CVE-2026-103624, another use-after-free in Contextual Tasks, allows for potential arbitrary code execution outside the sandbox for an attacker who has already compromised the renderer process. Additionally, CVE-2026-103628, an out-of-bounds write in WebGL, is rated as critical and allows for arbitrary code execution outside the sandbox. CVE-2026-103626, an incorrect authorization flaw in FileSystem on Windows, could lead to arbitrary code execution outside the sandbox through social engineering.

Other vulnerabilities disclosed in this batch focus on information disclosure. CVE-2026-103629, an integer overflow in Skia, and CVE-2026-103621, an integer overflow in Compositing, both allow for cross-origin data leakage. CVE-2026-103627, an information leak in SVG, enables remote attackers to obtain sensitive information.

All eleven vulnerabilities were addressed in Chrome version 154.0.8037.97. Users are strongly advised to update their Chrome browsers immediately to the latest version to protect themselves from these security risks. The consistent patching across multiple components in this single release highlights Google's proactive approach to addressing vulnerabilities discovered in its browser.

This batch of vulnerabilities underscores the importance of timely updates for web browsers, as flaws in core components like WebGL, V8, and WebRTC can have severe consequences, including arbitrary code execution. Users should ensure their browsers are configured for automatic updates or manually check for and install the latest version to mitigate these risks. The disclosure of multiple high and critical severity issues in a single release event emphasizes the need for continuous vigilance in browser security.

AI-written article. Grounded in 11 CVE records listed below.