Chrome 154 Rolls Out With Fixes for 108 Vulnerabilities, Including 11 Critical GPU, WebGL and ANGLE Flaws

Chrome 154 Rolls Out With Fixes for 108 Vulnerabilities, Including 11 Critical GPU, WebGL and ANGLE Flaws

Chrome 154 Rolls Out With Fixes for 108 Vulnerabilities, Including 11 Critical GPU, WebGL and ANGLE Flaws

Google has released Chrome 154 to the stable channel with patches for 108 vulnerabilities, including 11 rated critical. The batch is unusually heavy on graphics-code bugs: buffer overflows — three in ANGLE and one in WebGL — out-of-bounds writes in GPU and WebGL code, and use-after-free flaws in ServiceWorker, Fullscreen, WindowDialog and AdFilter. Google says none of the fixed vulnerabilities is known to be exploited in the wild, but users are advised to update as soon as possible. The release arrives less than three weeks after Google patched an actively exploited V8 zero-day, its sixth of the year.

Nine of the eleven critical bugs were reported by external researchers. In total, 32 of the 108 vulnerabilities came from outside Google, and the company has so far handed out $18,000 in bug bounty rewards — a number that will grow, since Google has yet to determine most of the payouts. Another 25 of the flaws are rated high severity, including a dozen use-after-free defects plus type confusion, uninitialized resource, buffer overflow, missing authorization, UI misinterpretation, incorrect authorization, improper output encoding, race condition and out-of-bounds write issues. The remainder are medium and low severity weaknesses spanning authorization, input validation, memory corruption, information leaks and memory safety.

The new stable versions are 154.0.8037.57/.58 for Windows and macOS and 154.0.8037.57 for Linux, now rolling out to users. Chrome updates itself by default, but enterprises and anyone managing pinned browser deployments should push the update through their usual channel rather than waiting for the rollout to reach every machine.

What Should You Do?

  1. Update now. Check Help > About in Chrome to force the update, or push 154.0.8037.57+ through your device management. Chrome-based browsers (Edge, Brave, Vivaldi, Opera and others) inherit Blink and V8 fixes on their own schedules — track those too.
  2. Prefer the 64-bit, sandboxed default configuration. Several of this release's critical bugs sit in GPU and WebGL code paths that hardened rendering configurations and GPU blocklists can blunt.
  3. Watch for a follow-up patch wave. Stable releases that fix large graphics-code batches sometimes get hit fast by researchers who diff the patches — a rapid second update within days is common, so don't declare the patch cycle "done" this week.
  4. Enterprise admins: review this month's browser policy posture. Renderer sandboxing, site isolation and extension allow-lists all reduce the blast radius of the memory bugs Chrome hasn't disclosed yet.

The WAF Angle

Browser patch waves are the quiet half of web security: every week a site gets popped through a memory bug, the incident gets attributed to the "sophisticated exploit," and the unpatched browser that served as the entry point gets forgotten. The practical move for web application defenders runs in the opposite direction — server-side detection of exploitation-ready payloads. Renderers crash before analysts connect the dots, so the WAF's job is to keep known exploit primitives (malformed graphics containers, oversized attribute structures, scripting probes against WebGL entry points) from ever reaching the browser. And the September cadence is a reminder worth passing to IT: Google has already confirmed six actively exploited V8 flaws this year, which means the question is never "will the browser be the weak link," only "which week."

Sources