Google Chrome
Stable Channel Update for Desktop
2937037625988113875 Sep 22, 2026 Source: Vendor
Imported by the Chrome release catcher from https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html. 108 security entries listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
116 lines
Showing 1–50 of 116 · page 1 of 3
CVE-2026-95350
BR2026-0000-014520
ANGLE
unclaimed
Critical: Buffer overflow in ANGLE (reported 2026-08-24)
Credited as Billy Jheng Bing Jhong
CVE-2026-95350
BR2026-0000-014521
ANGLE
unclaimed
Critical: Buffer overflow in ANGLE (reported 2026-08-24)
Credited as Muhammad Alifa Ramdhan
CVE-2026-95350
BR2026-0000-014522
ANGLE
unclaimed
Critical: Buffer overflow in ANGLE (reported 2026-08-24)
Credited as Pan Zhenpeng of STAR Labs SG Pte. LTd.
CVE-2026-95357
BR2026-0000-014523
GPU
unclaimed
Critical: Out of bounds write in GPU (reported 2026-07-01)
Credited as Anymous
CVE-2026-95339
BR2026-0000-014524
ServiceWorker
unclaimed
Critical: Use after free in ServiceWorker (reported 2026-08-18)
Credited as Andrew Boni
CVE-2026-95281
BR2026-0000-014525
ANGLE
unclaimed
Critical: Buffer overflow in ANGLE (reported 2026-08-24)
Credited as Muhammad Alifa Ramdhan of STAR Labs SG Pte. Ltd.
CVE-2026-95313
BR2026-0000-014526
Fullscreen
unclaimed
Critical: Use after free in Fullscreen (reported 2026-08-26)
Credited as WinD39 - Huynh Dinh Vu
CVE-2026-95349
BR2026-0000-014527
WebGL
unclaimed
Critical: Buffer overflow in WebGL (reported 2026-08-27)
Credited as Google
CVE-2026-95284
BR2026-0000-014528
ANGLE
unclaimed
Critical: Buffer overflow in ANGLE (reported 2026-09-03)
Credited as Muhammad Alifa Ramdhan (STARLABS SG)
CVE-2026-95322
BR2026-0000-014529
GPU
unclaimed
Critical: Out of bounds write in GPU (reported 2026-09-03)
Credited as David Sievers (@loknop)
CVE-2026-95329
BR2026-0000-014530
WebGL
unclaimed
Critical: Out of bounds write in WebGL (reported 2026-09-09)
Credited as Google
CVE-2026-95356
BR2026-0000-014531
WindowDialog
unclaimed
Critical: Use after free in WindowDialog (reported 2026-09-12)
Credited as Xinyang Ge
CVE-2026-95310
BR2026-0000-014532
AdFilter
unclaimed
Critical: Use after free in AdFilter (reported 2026-09-16)
Credited as Xinyang Ge
CVE-2026-95301
BR2026-0000-014533
Extensions
unclaimed
High: Missing authorization in Extensions (reported 2026-07-29)
Credited as OGINOME Tomohito
CVE-2026-95291
BR2026-0000-014534
SecurityIndicators
unclaimed
High: UI misrepresentation in SecurityIndicators (reported 2026-08-07)
Credited as NH DEV
CVE-2026-95355
BR2026-0000-014535
Navigation
unclaimed
High: Incorrect authorization in Navigation (reported 2026-05-01)
Credited as Google
CVE-2026-95315
BR2026-0000-014536
Aura
unclaimed
High: Use after free in Aura (reported 2026-05-29)
Credited as Google
CVE-2026-95298
BR2026-0000-014537
Browser
unclaimed
High: Use after free in Browser (reported 2026-06-05)
Credited as Google
CVE-2026-95372
BR2026-0000-014538
Chromecast
unclaimed
High: Use after free in Chromecast (reported 2026-07-15)
Credited as Google
CVE-2026-95324
BR2026-0000-014539
GPU
unclaimed
High: Uninitialized resource in GPU (reported 2026-07-22)
Credited as Google
CVE-2026-95283
BR2026-0000-014540
Tint
unclaimed
High: Buffer overflow in Tint (reported 2026-08-06)
Credited as Google
CVE-2026-95293
BR2026-0000-014541
GPU
unclaimed
High: Uninitialized resource in GPU (reported 2026-08-22)
Credited as TienPA - NGS Holdings
CVE-2026-95274
BR2026-0000-014542
DevTools
unclaimed
High: Improper output encoding in DevTools (reported 2026-08-26)
Credited as Google
CVE-2026-95282
BR2026-0000-014543
Platform
unclaimed
High: Use after free in Platform (reported 2026-08-26)
Credited as Google
CVE-2026-95373
BR2026-0000-014544
DevTools
unclaimed
High: Use after free in DevTools (reported 2026-08-26)
Credited as Google
CVE-2026-95277
BR2026-0000-014545
Views
unclaimed
High: Use after free in Views (reported 2026-08-26)
Credited as Google
CVE-2026-95348
BR2026-0000-014546
Bluetooth
unclaimed
High: Use after free in Bluetooth (reported 2026-08-29)
Credited as Google
CVE-2026-95335
BR2026-0000-014547
HID
unclaimed
High: Use after free in HID (reported 2026-09-01)
Credited as WinD39 - Huynh Dinh Vu
CVE-2026-95338
BR2026-0000-014548
PDFium
unclaimed
High: Use after free in PDFium (reported 2026-09-03)
Credited as SeungMyung Lee (@sm1ee)
CVE-2026-95338
BR2026-0000-014549
PDFium
unclaimed
High: Use after free in PDFium (reported 2026-09-03)
Credited as Siung kim (@ksw9722)
CVE-2026-95318
BR2026-0000-014550
Video
unclaimed
High: Buffer overflow in Video (reported 2026-09-03)
Credited as alex.laboirie
CVE-2026-95286
BR2026-0000-014551
Bindings
unclaimed
High: Type confusion in Bindings (reported 2026-09-05)
Credited as @bean5oup
CVE-2026-95365
BR2026-0000-014552
IndexedDB
unclaimed
High: Type confusion in IndexedDB (reported 2026-09-08)
Credited as HoneyBee
CVE-2026-95343
BR2026-0000-014553
WebAudio
unclaimed
High: Use after free in WebAudio (reported 2026-09-11)
Credited as HoneyBee
CVE-2026-95280
BR2026-0000-014554
V8
unclaimed
High: Race condition in V8 (reported 2026-09-12)
Credited as Google
CVE-2026-95304
BR2026-0000-014555
V8
unclaimed
High: Out of bounds write in V8 (reported 2026-09-12)
Credited as OpenAI Codex Security (amyb)
CVE-2026-95306
BR2026-0000-014556
V8
unclaimed
High: Type confusion in V8 (reported 2026-09-12)
Credited as OpenAI Codex Security (amyb)
CVE-2026-95299
BR2026-0000-014557
GPU
unclaimed
High: Use after free in GPU (reported 2026-09-15)
Credited as Google
CVE-2026-95351
BR2026-0000-014558
Views
unclaimed
High: Use after free in Views (reported 2026-09-16)
Credited as Xinyang Ge
CVE-2026-95287
BR2026-0000-014559
Navigation
unclaimed
Medium: Missing authorization in Navigation (reported 2026-03-23)
Credited as Google
CVE-2026-95366
BR2026-0000-014560
Core
unclaimed
Medium: Use of released resource in Core (reported 2026-03-28)
Credited as Google
CVE-2026-95382
BR2026-0000-014561
Auth
unclaimed
Medium: Improper input validation in Auth (reported 2026-03-28)
Credited as Google
CVE-2026-95381
BR2026-0000-014562
Printing
unclaimed
Medium: Improper input validation in Printing (reported 2026-03-30)
Credited as Google
CVE-2026-95331
BR2026-0000-014563
ANGLE
unclaimed
Medium: Out of bounds write in ANGLE (reported 2026-04-06)
Credited as Google
CVE-2026-95297
BR2026-0000-014564
Contextual Tasks
unclaimed
Medium: Missing authorization in Contextual Tasks (reported 2026-04-11)
Credited as Google
CVE-2026-95375
BR2026-0000-014565
BrowserTag
unclaimed
Medium: Incorrect authorization in BrowserTag (reported 2026-04-13)
Credited as Google
CVE-2026-95302
BR2026-0000-014566
WebAPKs
unclaimed
Medium: Incorrect authorization in WebAPKs (reported 2026-04-13)
Credited as Google
CVE-2026-95362
BR2026-0000-014567
DevTools
unclaimed
Medium: Cross-site request forgery in DevTools (reported 2026-05-10)
Credited as Google
CVE-2026-95369
BR2026-0000-014568
XML
unclaimed
Medium: Inappropriate implementation in XML (reported 2026-05-14)
Credited as Google
CVE-2026-95376
BR2026-0000-014569
DevTools
unclaimed
Medium: Externally controlled reference in DevTools (reported 2026-05-14)
Credited as Google