Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Google released a Chrome Stable update fixing 32 security vulnerabilities across Windows, macOS, and Linux, including one critical and multiple high-severity flaws in V8, ANGLE, GPU, WebGPU, Bluetooth, Passwords, and UI components.

Chrome version 154.0.8037.92/.93 is being rolled out to Windows and Mac users, while Linux users will receive version 154.0.8037.92. Google said it will deliver the update to users over the coming days and weeks.

The most serious flaw, CVE-2026-102331, is a critical ANGLE buffer overflow that can corrupt memory and potentially enable code execution in Chrome’s browser context.

The update also fixes several high-severity vulnerabilities in Chrome’s V8 JavaScript engine. These include multiple type confusion issues, tracked as CVE-2026-102299, CVE-2026-102323, CVE-2026-102326, CVE-2026-102328, and CVE-2026-102321.

Type confusion flaws occur when software incorrectly handles an object as a different type, which may lead to memory corruption or arbitrary code execution.

Google also patched CVE-2026-102302, a high-severity buffer overflow in V8. Because V8 processes JavaScript from websites, attackers could use a malicious webpage to trigger a browser crash or exploit the vulnerability.

Chrome Update With 32 Security Fixes

Google also fixed several other memory-safety issues in GPU, WebGPU, WebGL, Dawn, Skia, Media, Bluetooth, Views, Passwords, FullScreen, and Picture-in-Picture components.

Notable fixes include use-after-free flaws in Bluetooth, Views, Passwords, FullScreen, and Picture-in-Picture. A use-after-free vulnerability occurs when a program continues using a memory location after releasing it. Such flaws are frequently valuable to attackers because they can sometimes be chained with other weaknesses to gain code execution.

Google also addressed CVE-2026-102329, a high-severity cross-site scripting issue in WebUI. Cross-site scripting flaws can allow attackers to inject malicious scripts into trusted browser pages or interfaces, potentially exposing sensitive information or manipulating browser settings.

Other security fixes include improper privilege management in Mojo, missing authorization in CORS and Payments, incorrect authorization in WebView and SiteIsolation, and UI misrepresentation issues affecting the Omnibox, TabStrip, and SignIn components.

Google has restricted access to technical bug details for several vulnerabilities until most Chrome users receive the update. This practice is intended to reduce the likelihood of exploitation before systems are patched.

Users should update Chrome immediately by opening the browser menu, selecting Help, and choosing About Google Chrome. Chrome will automatically check for the latest release and prompt users to relaunch the browser after installation.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux appeared first on Cyber Security News.