Google Chrome
Stable Channel Update for Desktop: 154.0.8037.92/.93
154.0.8037.92/.93 Sep 29, 2026 Source: Vendor
Imported by the Chrome release catcher from https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html. 32 security entries listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
32 lines
Showing 1–32 of 32
CVE-2026-102331
BR2026-0000-015571
ANGLE
unclaimed
Critical: Buffer overflow in ANGLE (reported 2026-08-24)
Credited as @mfx
CVE-2026-102317
BR2026-0000-015572
Mojo
unclaimed
High: Improper privilege management in Mojo (reported 2026-05-28)
Credited as Google
CVE-2026-102312
BR2026-0000-015573
Omnibox
unclaimed
High: UI misrepresentation in Omnibox (reported 2026-08-24)
Credited as jodyritonga
CVE-2026-102313
BR2026-0000-015574
ANGLE
unclaimed
High: Uninitialized resource in ANGLE (reported 2026-09-03)
Credited as Google
CVE-2026-102299
BR2026-0000-015575
V8
unclaimed
High: Type confusion in V8 (reported 2026-09-04)
Credited as Andrew Boni
CVE-2026-102306
BR2026-0000-015576
Bluetooth
unclaimed
High: Use after free in Bluetooth (reported 2026-09-04)
Credited as Google
CVE-2026-102307
BR2026-0000-015577
Dawn
unclaimed
High: Uninitialized resource in Dawn (reported 2026-09-04)
Credited as Google
CVE-2026-102323
BR2026-0000-015578
V8
unclaimed
High: Type confusion in V8 (reported 2026-09-10)
Credited as OpenAI Codex Security (amyb)
CVE-2026-102303
BR2026-0000-015579
GPU
unclaimed
High: Uninitialized resource in GPU (reported 2026-09-10)
Credited as Google
CVE-2026-102311
BR2026-0000-015580
GPU
unclaimed
High: Uninitialized resource in GPU (reported 2026-09-10)
Credited as Google
CVE-2026-102300
BR2026-0000-015581
WebGPU
unclaimed
High: Uninitialized resource in WebGPU (reported 2026-09-11)
Credited as Arni Hardarson (Neonix Security)
CVE-2026-102326
BR2026-0000-015582
V8
unclaimed
High: Type confusion in V8 (reported 2026-09-11)
Credited as OpenAI Codex Security (amyb)
CVE-2026-102316
BR2026-0000-015583
Views
unclaimed
High: Use after free in Views (reported 2026-09-11)
Credited as Xinyang Ge
CVE-2026-102304
BR2026-0000-015584
Passwords
unclaimed
High: Use after free in Passwords (reported 2026-09-11)
Credited as Xinyang Ge
CVE-2026-102328
BR2026-0000-015585
V8
unclaimed
High: Type confusion in V8 (reported 2026-09-12)
Credited as OpenAI Codex Security (amyb)
CVE-2026-102309
BR2026-0000-015586
FullScreen
unclaimed
High: Use after free in FullScreen (reported 2026-09-13)
Credited as sean geofrey
CVE-2026-102325
BR2026-0000-015587
Skia
unclaimed
High: Uninitialized resource in Skia (reported 2026-09-15)
Credited as Google
CVE-2026-102308
BR2026-0000-015588
Views
unclaimed
High: Use after free in Views (reported 2026-09-15)
Credited as Google
CVE-2026-102301
BR2026-0000-015589
GPU
unclaimed
High: Out of bounds write in GPU (reported 2026-09-15)
Credited as Google
CVE-2026-102319
BR2026-0000-015590
GPU
unclaimed
High: Uninitialized resource in GPU (reported 2026-09-15)
Credited as Google
CVE-2026-102324
BR2026-0000-015591
PictureInPicture
unclaimed
High: Use after free in PictureInPicture (reported 2026-09-15)
Credited as Blockian Creator of Kritt and Open-Kritt
CVE-2026-102318
BR2026-0000-015592
WebGL
unclaimed
High: Out of bounds read in WebGL (reported 2026-09-16)
Credited as Google
CVE-2026-102329
BR2026-0000-015593
WebUI
unclaimed
High: Cross-site scripting in WebUI (reported 2026-09-18)
Credited as chipsec
CVE-2026-102315
BR2026-0000-015594
Media
unclaimed
High: Uninitialized resource in Media (reported 2026-09-18)
Credited as Google
CVE-2026-102302
BR2026-0000-015595
V8
unclaimed
High: Buffer overflow in V8 (reported 2026-09-19)
Credited as Google
CVE-2026-102321
BR2026-0000-015596
V8
unclaimed
High: Type confusion in V8 (reported 2026-09-23)
Credited as Taisic Yun (@taisic_) of Theori
CVE-2026-102321
BR2026-0000-015597
V8
unclaimed
High: Type confusion in V8 (reported 2026-09-23)
Credited as with Xint
CVE-2026-102310
BR2026-0000-015598
Payments
unclaimed
Low: Missing authorization in Payments (reported 2026-01-22)
Credited as Autodidact
CVE-2026-102327
BR2026-0000-015599
WebView
unclaimed
Low: Incorrect authorization in WebView (reported 2026-03-25)
Credited as Google
CVE-2026-102330
BR2026-0000-015600
SiteIsolation
unclaimed
Low: Incorrect authorization in SiteIsolation (reported 2026-04-02)
Credited as Google
CVE-2026-102314
BR2026-0000-015601
TabStrip
unclaimed
Low: UI misrepresentation in TabStrip (reported 2026-05-17)
Credited as Google
CVE-2026-102305
BR2026-0000-015602
SignIn
unclaimed
Low: UI misrepresentation in SignIn (reported 2026-07-09)
Credited as Google