VYPR
Published Sep 29, 2026· Updated Oct 1, 2026· 1 source

Chromium: 25 Vulnerabilities Patched in Single Batch, Including Critical Use-After-Free and GPU Flaws

Key findings • Google Chrome patched 25 vulnerabilities on September 29, 2026, including two critical and multiple high-severity flaws. • Critical vulnerabilities include use-after-free in Pa…

Key findings

  • Google Chrome patched 25 vulnerabilities on September 29, 2026, including two critical and multiple high-severity flaws.
  • Critical vulnerabilities include use-after-free in Passwords and out-of-bounds write in GPU, potentially allowing arbitrary code execution.
  • High-severity flaws span components like Mojo, IndexedDB, XML, and various use-after-free bugs in core browser functions.
  • Patches were released in Chrome versions 154.0.8037.92 and 154.0.8037.93 for various operating systems.
  • Vulnerabilities affect components including V8, ANGLE, WebView, GPU, and UI elements, with diverse attack vectors.

On September 29, 2026, Google released an update for Chrome addressing a significant batch of 25 vulnerabilities, including two critical and multiple high-severity flaws. The vulnerabilities span various components of the browser, such as the V8 JavaScript engine, ANGLE graphics engine, Bluetooth, GPU, and UI elements. The patches were released in Chrome versions 154.0.8037.92 and 154.0.8037.93 for various operating systems.

Critical Vulnerabilities

The most severe issues include a use-after-free vulnerability in the Passwords component (CVE-2026-102304), rated Critical with a CVSSv3 score of 9.6, and an out-of-bounds write in the GPU component (CVE-2026-102301), rated High with a CVSSv3 score of 8.3. These flaws could allow remote attackers who compromised the renderer process to execute arbitrary code outside the sandbox.

High-Severity Flaws

Several high-severity vulnerabilities were also addressed:

  • Improper Privilege Management: CVE-2026-102317 in Mojo on Windows, rated High (CVSSv3 8.6), allowed local attackers to potentially execute arbitrary code outside the sandbox.
  • Inappropriate Implementation: CVE-2026-95369 in XML and CVE-2026-95368 in IndexedDB, both rated High with CVSSv3 8.8, allowed remote attackers to execute arbitrary code inside the sandbox.
  • Type Confusion: CVE-2026-95365 in IndexedDB, rated High (CVSSv3 8.8), also allowed remote attackers to potentially execute arbitrary code inside the sandbox.
  • Use After Free: Multiple use-after-free vulnerabilities were patched, including CVE-2026-95353 in Bindings, CVE-2026-95351 in Views, CVE-2026-95348 in Bluetooth, CVE-2026-95345 in Actor, and CVE-2026-95343 in WebAudio. These vulnerabilities, rated High with CVSSv3 scores ranging from 8.3 to 8.8, could permit remote attackers to execute arbitrary code inside or outside the sandbox.
  • Cross-Site Request Forgery: CVE-2026-95362 in DevTools, rated High (CVSSv3 8.8), allowed remote attackers to bypass web origin policy.
  • Improper Input Validation: CVE-2026-95381 in Printing, rated High (CVSSv3 8.3), allowed remote attackers to potentially execute arbitrary code outside the sandbox.

Medium and Low Severity Issues

The batch also included several medium and low-severity vulnerabilities. These range from missing authorization and incorrect authorization in components like SiteIsolation, CORS, Payments, and DevTools, to UI misrepresentation, uninitialized resources, and race conditions in components such as TabStrip, Media, Transactions Platform, Auth, Views, NFC, and V8. While these flaws may not directly lead to code execution, they could enable attackers to bypass policies, spoof UI elements, or leak sensitive information.

Affected Versions and Patching

All disclosed vulnerabilities were fixed in Google Chrome versions 154.0.8037.92 and 154.0.8037.93. Users are strongly advised to update their Chrome browsers to the latest available version to protect against these security risks. The rapid patching of such a large number of vulnerabilities highlights the ongoing efforts by the Chromium security team to maintain browser security.

The disclosure of 25 vulnerabilities in a single batch underscores the complexity of modern browser security and the continuous need for vigilance from both developers and users. Staying updated with the latest patches is crucial for mitigating the risks associated with these types of security disclosures. The variety of vulnerability types and affected components indicates a broad range of potential attack vectors that have been addressed by this update.

Synthesized by Vypr AI