Google's latest Chrome update closes 11 security holes, and none of them is known to have been used against anyone. The Stable channel moved to version 154.0.8037.97 for Linux, and 154.0.8037.97 or .98 for Windows and Mac, on Thursday 1 October, US time. It's rolling out over the coming days and weeks.

One of the 11 is rated critical. It's an out-of-bounds write in WebGL, the part of Chrome that draws 3D graphics in web pages. Google's own team found it back in August, so it's been fixed before anyone outside the company got a chance to find it.

What's in the update

Google listed the fixes in its Chrome Releases post. There's one critical bug, nine rated high and one rated medium.

Photo: Dietmar Rabich / Wikimedia Commons (CC BY-SA 4.0), cropped

The critical one is CVE-2026-103628. The US National Vulnerability Database's entry, which is based on Google's description, says it could let a remote attacker run code outside Chrome's sandbox using a crafted web page. The sandbox is the wall that's meant to stop a bad page reaching the rest of your computer. A bug that gets past it is the kind Google rates highest. Google reported it internally on 21 August.

The nine high-severity fixes are spread across Chrome:

  • an incorrect authorization bug in FileSystem
  • integer overflows in Compositing and in Skia, Chrome's graphics library
  • use-after-free bugs in FedCM, the sign-in feature, and in Contextual Tasks, SVG and MediaStream
  • a type confusion bug in V8, Chrome's JavaScript engine
  • a buffer overflow in WebRTC, which handles video calls

The medium one is an information leak in SVG.

Those ratings follow Chromium's published severity guidelines. Roughly, critical means a bug could let a web page break out of the sandbox and reach your system. High covers bugs that could let a page run code inside the sandbox, or get at data it shouldn't. On its own, a high-rated bug is usually one step of an attack, not the whole thing. That's why attackers try to chain them together, and why fixing nine at once takes a lot of possible links out of play.

The most important line is the one that's missing. Google's post doesn't say any of these bugs has been exploited. When Google knows an exploit is out there, its release post says so in plain words. That warning is what sends a bug onto CISA's list of exploited flaws, like the Chromium bug we covered in September in Chromium hit the KEV. There's no such warning this time, and NVD's records for the new bugs don't list any exploitation.

Who found them

Google reported six of the 11 itself. They include the critical WebGL bug, the V8 type confusion and the Skia overflow. Google's post says many of its security bugs are caught by automated testing tools like AddressSanitizer, MemorySanitizer, libFuzzer and AFL. Those tools hammer the code with odd inputs until something breaks, well before a release goes out.

Outside researchers reported the other five. A researcher credited as xinyang found three of them, all use-after-free bugs, in FedCM, SVG and MediaStream. Another, credited as xuanocto1221, found the Contextual Tasks bug.

The last one stands out. Google credits the WebRTC buffer overflow, CVE-2026-103631, to "Xinyang Ge (Anthropic), assisted by Claude." It was reported on 28 September and fixed in a stable release three days later. That's quick, and it's another sign AI tools are now part of how bugs get found and fixed. Google, OpenAI and Anthropic have all been handing their models to defenders first, as we reported in Fairwind named the defenders.

Google lists the reward for each of the five outside reports as still to be decided, and its own finds don't carry a bounty. So there aren't any dollar figures for this batch yet. Google also keeps bug details locked until most users have updated, which is standard. The thinking is simple. A published bug report is a map for anyone who wants to attack people who haven't patched yet.

How to get it

Chrome updates itself, but it only finishes the job when you restart it. Here's the quickest way to check you've got the fixed version:

  • Open Chrome's menu, go to Help, then About Google Chrome.
  • Chrome will check for the update and download it.
  • Click Relaunch when it's ready. Your tabs come back.

You want 154.0.8037.97 or later. If the About page shows an older number and says you're up to date, give it a day. Google is rolling it out in stages.

On Android, Chrome 154.0.8037.126 started rolling out on Google Play the same day. Google says Android releases carry the same security fixes as the matching desktop build unless it says otherwise.

Businesses on Chrome's Extended Stable channel, which moves to a new major version every eight weeks instead of every four, got 152.0.7977.152 for Windows and Mac on Friday 2 October. Google's Extended Stable post doesn't say which security fixes it includes.

If you look after a fleet of machines, the download isn't the slow part. The restart is. Chrome's enterprise policies let admins nag users to relaunch, or force a relaunch after a set time, and this is a good week to tighten that window. A patched browser that's still running the old version in memory isn't patched.

Why a quiet patch is good news

The Chrome updates that make headlines are the emergency ones, where Google admits an exploit is already out there and everyone scrambles. This isn't one of those. It's the routine kind. Bugs get found by Google's own tools and by researchers who report them privately, then they get fixed on schedule.

That routine is what keeps the emergencies rare. Every bug in this batch reached Google through its own testing or a private report, and none is known to have been used against Chrome users. That's the system doing its job.

Other browsers built on Chromium, including Microsoft Edge, Brave, Opera and Vivaldi, share most of this code. They usually pick up Chromium security fixes in their own updates, so check those too.

What I'm leaving out

You won't get a technical breakdown of these bugs here. Google has restricted the bug reports for now, and that's the right call. I'm not going to guess at how the WebGL or WebRTC bugs work, or how someone might set them off.

What matters to you is the version number. Get to 154.0.8037.97 or later, restart the browser, and you're covered for all 11.