Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESGOOGLEVERIFIED

PUBLISHER UPDATE · GOOGLE-CHROME-154.0.8037.57

GOOGLE-CHROME-154.0.8037.57 release notes and known issues

Stable Channel Update for Desktop

Scope: Google Chrome. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

The Chrome team is delighted to announce the promotion of Chrome 154 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks. Chrome 154.0.8037.57 (Linux) 154.0.8037.57/.58 Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log . Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 154. Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed. This update includes 108 security fixes. Please see the Chrome Security Page for more information. [$5,000][ 551573368 ] Critical CVE-2026-95350: Buffer overflow in ANGLE. Reported by Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng of STAR Labs SG Pte. LTd. on 2026-08-24 [$2,500][ 530045332 ] Critical CVE-2026-95357: Out of bounds write in GPU. Reported by Anymous on 2026-07-01 [TBD][ 548585299 ] Critical CVE-2026-95339: Use after free in ServiceWorker. Reported by Andrew Boni on 2026-08-18 [TBD][ 551708184 ] Critical CVE-2026-95281: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan of STAR Labs SG Pte. Ltd. on 2026-08-24 [TBD][ 552665794 ] Critical CVE-2026-95313: Use after free in Fullscreen. Reported by WinD39 - Huynh Dinh Vu on 2026-08-26 [N/A][ 553172761 ] Critical CVE-2026-95349: Buffer overflow in WebGL. Reported by Google on 2026-08-27 [TBD][ 556435507 ] Critical CVE-2026-95284: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan (STARLABS SG) on 2026-09-03 [TBD][ 556576992 ] Critical CVE-2026-95322: Out of bounds write in GPU. Reported by David Sievers (@loknop) on 2026-09-03 [N/A][ 559320837 ] Critical CVE-2026-95329: Out of bounds write in WebGL. Reported by Google on 2026-09-09 [TBD][ 560439699 ] Critical CVE-2026-95356: Use after free in WindowDialog. Reported by Xinyang Ge on 2026-09-12 [TBD][ 562151598 ] Critical CVE-2026-95310: Use after free in AdFilter. Reported by Xinyang Ge on 2026-09-16 [$5,000][ 540265100 ] High CVE-2026-95301: Missing authorization in Extensions. Reported by OGINOME Tomohito on 2026-07-29 [$5,000][ 543471693 ] High CVE-2026-95291: UI misrepresentation in SecurityIndicators. Reported by NH DEV on 2026-08-07 [N/A][ 508462481 ] High CVE-2026-95355: Incorrect authorization in Navigation. Reported by Google on 2026-05-01 [N/A][ 517661385 ] High CVE-2026-95315: Use after free in Aura. Reported by Google on 2026-05-29 [N/A][ 520516206 ] High CVE-2026-95298: Use after free in Browser. Reported by Google on 2026-06-05 [N/A][ 534997484 ] High CVE-2026-95372: Use after free in Chromecast. Reported by Google on 2026-07-15 [N/A][ 537857253 ] High CVE-2026-95324: Uninitialized resource in GPU. Reported by Google on 2026-07-22 [N/A][ 543141419 ] High CVE-2026-95283: Buffer overflow in Tint. Reported by Google on 2026-08-06 [TBD][ 550953039 ] High CVE-2026-95293: Uninitialized resource in GPU. Reported by TienPA - NGS Holdings on 2026-08-22 [N/A][ 553116160 ] High CVE-2026-95274: Improper output encoding in DevTools. Reported by Google on 2026-08-26 [N/A][ 553129513 ] High CVE-2026-95282: Use after free in Platform. Reported by Google on 2026-08-26 [N/A][ 553130481 ] High CVE-2026-95373: Use after free in DevTools. Reported by Google on 2026-08-26 [N/A][ 553136141 ] High CVE-2026-95277: Use after free in Views. Reported by Google on 2026-08-26 [N/A][ 554558320 ] High CVE-2026-95348: Use after free in Bluetooth. Reported by Google on 2026-08-29 [TBD][ 555299641 ] High CVE-2026-95335: Use after free in HID. Reported by WinD39 - Huynh Dinh Vu on 2026-09-01 [TBD][ 556535630 ] High CVE-2026-95338: Use after free in PDFium. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) on 2026-09-03 [TBD][ 556576976 ] High CVE-2026-95318: Buffer overflow in Video. Reported by alex.laboirie on 2

Improvements and security content

  • The Chrome team is delighted to announce the promotion of Chrome 154 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks. Chrome 154.0.8037.57 (Linux) 154.0.8037.57/.58 Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log . Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 154. Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed. This update includes 108 security fixes. Please see the Chrome Security Page for more information. [$5,000][ 551573368 ] Critical CVE-2026-95350: Buffer overflow in ANGLE. Reported by Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng of STAR Labs SG Pte. LTd. on 2026-08-24 [$2,500][ 530045332 ] Critical CVE-2026-95357: Out of bounds write in GPU. Reported by Anymous on 2026-07-01 [TBD][ 548585299 ] Critical CVE-2026-95339: Use after free in ServiceWorker. Reported by Andrew Boni on 2026-08-18 [TBD][ 551708184 ] Critical CVE-2026-95281: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan of STAR Labs SG Pte. Ltd. on 2026-08-24 [TBD][ 552665794 ] Critical CVE-2026-95313: Use after free in Fullscreen. Reported by WinD39 - Huynh Dinh Vu on 2026-08-26 [N/A][ 553172761 ] Critical CVE-2026-95349: Buffer overflow in WebGL. Reported by Google on 2026-08-27 [TBD][ 556435507 ] Critical CVE-2026-95284: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan (STARLABS SG) on 2026-09-03 [TBD][ 556576992 ] Critical CVE-2026-95322: Out of bounds write in GPU. Reported by David Sievers (@loknop) on 2026-09-03 [N/A][ 559320837 ] Critical CVE-2026-95329: Out of bounds write in WebGL. Reported by Google on 2026-09-09 [TBD][ 560439699 ] Critical CVE-2026-95356: Use after free in WindowDialog. Reported by Xinyang Ge on 2026-09-12 [TBD][ 562151598 ] Critical CVE-2026-95310: Use after free in AdFilter. Reported by Xinyang Ge on 2026-09-16 [$5,000][ 540265100 ] High CVE-2026-95301: Missing authorization in Extensions. Reported by OGINOME Tomohito on 2026-07-29 [$5,000][ 543471693 ] High CVE-2026-95291: UI misrepresentation in SecurityIndicators. Reported by NH DEV on 2026-08-07 [N/A][ 508462481 ] High CVE-2026-95355: Incorrect authorization in Navigation. Reported by Google on 2026-05-01 [N/A][ 517661385 ] High CVE-2026-95315: Use after free in Aura. Reported by Google on 2026-05-29 [N/A][ 520516206 ] High CVE-2026-95298: Use after free in Browser. Reported by Google on 2026-06-05 [N/A][ 534997484 ] High CVE-2026-95372: Use after free in Chromecast. Reported by Google on 2026-07-15 [N/A][ 537857253 ] High CVE-2026-95324: Uninitialized resource in GPU. Reported by Google on 2026-07-22 [N/A][ 543141419 ] High CVE-2026-95283: Buffer overflow in Tint. Reported by Google on 2026-08-06 [TBD][ 550953039 ] High CVE-2026-95293: Uninitialized resource in GPU. Reported by TienPA - NGS Holdings on 2026-08-22 [N/A][ 553116160 ] High CVE-2026-95274: Improper output encoding in DevTools. Reported by Google on 2026-08-26 [N/A][ 553129513 ] High CVE-2026-95282: Use after free in Platform. Reported by Google on 2026-08-26 [N/A][ 553130481 ] High CVE-2026-95373: Use after free in DevTools. Reported by Google on 2026-08-26 [N/A][ 553136141 ] High CVE-2026-95277: Use after free in Views. Reported by Google on 2026-08-26 [N/A][ 554558320 ] High CVE-2026-95348: Use after free in Bluetooth. Reported by Google on 2026-08-29 [TBD][ 555299641 ] High CVE-2026-95335: Use after free in HID. Reported by WinD39 - Huynh Dinh Vu on 2026-09-01 [TBD][ 556535630 ] High CVE-2026-95338: Use after free in PDFium. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) on 2026-09-03 [TBD][ 556576976 ] High CVE-2026-95318: Buffer overflow in Video. Reported by alex.laboirie on 2

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Google Chrome

Affected versions

  • 154.0.8037.57

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

GOOGLEVERIFIED

Stable Channel Update for Desktop

Checked 26 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source