Google released Chrome Stable 154.0.8037.92/.93 for Windows and macOS and 154.0.8037.92 for Linux, remediating 32 security vulnerabilities. The most severe issue, CVE-2026-102331, is a critical buffer overflow in ANGLE that can corrupt memory and potentially enable code execution in Chrome’s browser context.
The update also fixes 26 high-severity issues, including V8 type-confusion and buffer-overflow flaws potentially reachable through malicious webpages, along with use-after-free, out-of-bounds, and uninitialized-resource bugs. Affected components include GPU, WebGPU, Mojo, Bluetooth, Passwords, WebUI, CORS, Payments, WebView, and SiteIsolation. Google is restricting some technical details until adoption increases; it reported no active exploitation and advised users to update and relaunch Chrome promptly.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Researcher @mfx reported CVE-2026-102331, a critical buffer-overflow vulnerability in Chrome's ANGLE component, to Google.
Google released Chrome Stable 154.0.8037.92/.93 for Windows and macOS and 154.0.8037.92 for Linux, remediating 32 security vulnerabilities. The fixes include critical ANGLE buffer overflow CVE-2026-102331 and 26 high-severity issues affecting V8, GPU, WebGPU, Mojo, Bluetooth, WebUI, Passwords, and other components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.