Chromium: 25 Vulnerabilities Patched in Single Batch, Including Critical Use-After-Free and GPU Flaws
Google Chrome released an update on September 29, 2026, patching 25 vulnerabilities, including critical flaws in Passwords and GPU components, and multiple high-severity issues across various modules.

Key findings
- Google Chrome patched 25 vulnerabilities on September 29, 2026, including two critical and multiple high-severity flaws.
- Critical vulnerabilities include use-after-free in Passwords and out-of-bounds write in GPU, potentially allowing arbitrary code execution.
- High-severity flaws span components like Mojo, IndexedDB, XML, and various use-after-free bugs in core browser functions.
- Patches were released in Chrome versions 154.0.8037.92 and 154.0.8037.93 for various operating systems.
- Vulnerabilities affect components including V8, ANGLE, WebView, GPU, and UI elements, with diverse attack vectors.
On September 29, 2026, Google released an update for Chrome addressing a significant batch of 25 vulnerabilities, including two critical and multiple high-severity flaws. The vulnerabilities span various components of the browser, such as the V8 JavaScript engine, ANGLE graphics engine, Bluetooth, GPU, and UI elements. The patches were released in Chrome versions 154.0.8037.92 and 154.0.8037.93 for various operating systems.
Critical Vulnerabilities
The most severe issues include a use-after-free vulnerability in the Passwords component (CVE-2026-102304), rated Critical with a CVSSv3 score of 9.6, and an out-of-bounds write in the GPU component (CVE-2026-102301), rated High with a CVSSv3 score of 8.3. These flaws could allow remote attackers who compromised the renderer process to execute arbitrary code outside the sandbox.
High-Severity Flaws
Several high-severity vulnerabilities were also addressed:
- Improper Privilege Management:
CVE-2026-102317in Mojo on Windows, rated High (CVSSv3 8.6), allowed local attackers to potentially execute arbitrary code outside the sandbox. - Inappropriate Implementation:
CVE-2026-95369in XML andCVE-2026-95368in IndexedDB, both rated High with CVSSv3 8.8, allowed remote attackers to execute arbitrary code inside the sandbox. - Type Confusion:
CVE-2026-95365in IndexedDB, rated High (CVSSv3 8.8), also allowed remote attackers to potentially execute arbitrary code inside the sandbox. - Use After Free: Multiple use-after-free vulnerabilities were patched, including
CVE-2026-95353in Bindings,CVE-2026-95351in Views,CVE-2026-95348in Bluetooth,CVE-2026-95345in Actor, andCVE-2026-95343in WebAudio. These vulnerabilities, rated High with CVSSv3 scores ranging from 8.3 to 8.8, could permit remote attackers to execute arbitrary code inside or outside the sandbox. - Cross-Site Request Forgery:
CVE-2026-95362in DevTools, rated High (CVSSv3 8.8), allowed remote attackers to bypass web origin policy. - Improper Input Validation:
CVE-2026-95381in Printing, rated High (CVSSv3 8.3), allowed remote attackers to potentially execute arbitrary code outside the sandbox.
Medium and Low Severity Issues
The batch also included several medium and low-severity vulnerabilities. These range from missing authorization and incorrect authorization in components like SiteIsolation, CORS, Payments, and DevTools, to UI misrepresentation, uninitialized resources, and race conditions in components such as TabStrip, Media, Transactions Platform, Auth, Views, NFC, and V8. While these flaws may not directly lead to code execution, they could enable attackers to bypass policies, spoof UI elements, or leak sensitive information.
Affected Versions and Patching
All disclosed vulnerabilities were fixed in Google Chrome versions 154.0.8037.92 and 154.0.8037.93. Users are strongly advised to update their Chrome browsers to the latest available version to protect against these security risks. The rapid patching of such a large number of vulnerabilities highlights the ongoing efforts by the Chromium security team to maintain browser security.
The disclosure of 25 vulnerabilities in a single batch underscores the complexity of modern browser security and the continuous need for vigilance from both developers and users. Staying updated with the latest patches is crucial for mitigating the risks associated with these types of security disclosures. The variety of vulnerability types and affected components indicates a broad range of potential attack vectors that have been addressed by this update.