Back to news
Cybersecurity Alert
September 28, 2026 by EmailMeNow IT Consulting

Chrome 154 Patches 108 Flaws Including 11 Critical — Update Desktop and Android

Google Chrome 154 (Sept 22) fixes 108 security issues, 11 Critical, including ANGLE and GPU bugs. Audits (ideal 100%): googleblog.com 82%, malwarebytes.com 71%, google.com 55%, chrome.google.com 35%.

Source: Google Chrome Releases · Malwarebytes

NewsGoogle ChromeVulnerability DisclosureBrowser SecurityCVEPhishingMFAYubiKeyAuthenticator AppsCybersecurity
Laptop showing a generic browser About window with an update available and a Relaunch prompt

Google promoted Chrome 154 to the desktop stable channel on September 22, 2026. The Chrome Releases note lists 108 security fixes, including 11 Critical. Builds are 154.0.8037.57 on Linux and 154.0.8037.57/.58 on Windows and Mac. The same-day Android 154 package (154.0.8037.57) carries the same security fixes unless Google notes otherwise.

Malwarebytes (Sept 24) and SecurityWeek recapped the same bulletin. Google has not reported in-the-wild exploitation for this batch. That is not a reason to wait: a crafted page hitting ANGLE, GPU, or WebGL is enough of a reason to relaunch.

If About Chrome still shows 150 or 148, you are not on this patch set.

Official notes: Stable Channel Update for Desktop, Sept 22

Laptop showing a generic browser About window with an update available and a Relaunch prompt

Snapshot

FieldDetail
Desktop stableSept 22, 2026 — Chrome 154.0.8037.57 (Linux) / .57/.58 (Windows, Mac)
Android154.0.8037.57 on Google Play (same security set)
Totals108 fixes — 11 Critical, 25 High, 47 Medium, 25 Low
Who found themGoogle 76; external researchers 32 (PCWorld / SecurityWeek)
Bounties so far$18,000 posted; many external items still TBD
In the wild (at release)Not reported
CourtListener0 matching RECAP dockets for this patch cycle (searched Sept 28, 2026)

Chrome 155 on Android (155.0.8059.16, Sept 23) is an Early Stable slice for a small share of Play users. Google describes stability and performance, not a second 108-fix bulletin. Do not chase Beta. Get 154 first, then let 155 roll out.

Extended Stable moved to 152.0.7977.140 the same day. That channel is a back-level Chromium, not 154.

Critical fixes to take seriously

A malicious webpage is the usual trigger. We do not publish exploit steps. Names and components come from Google’s list:

CVEComponentClass
CVE-2026-95350ANGLEBuffer overflow
CVE-2026-95281ANGLEBuffer overflow
CVE-2026-95284ANGLEBuffer overflow
CVE-2026-95349WebGLBuffer overflow
CVE-2026-95357GPUOut-of-bounds write
CVE-2026-95322GPUOut-of-bounds write
CVE-2026-95329WebGLOut-of-bounds write
CVE-2026-95339ServiceWorkerUse after free
CVE-2026-95313FullscreenUse after free
CVE-2026-95356WindowDialogUse after free
CVE-2026-95310AdFilterUse after free

Nine of the eleven Critical items were external reports. High-severity follow-ons include use-after-free in Extensions-adjacent UI, V8 type-confusion / out-of-bounds write, and PDFium. Treat Chromium-based Edge and other forks as separate patch clocks.

How to update

Type these paths. Do not use an “urgent Chrome update” link from email, search ads, or a pop-up.

Desktop (Windows, macOS, Linux)

StepAction
1Open Chrome
2Menu ⋮ → Help → About Google Chrome, or paste chrome://settings/help
3Wait for the check to finish, then Relaunch
4Confirm 154.0.8037.57 or .58 (or newer)

macOS: Chrome menu → About Google Chrome.

Linux: If the in-browser updater is stuck, use Google’s repo package or google.com/chrome — never a third-party “Chrome download” page.

Android

StepAction
1Open the Play Store app (search it; do not follow an SMS)
2Profile → Manage apps → find Chrome → Update
3In Chrome: ⋮ → Settings → About Chrome
4Confirm 154.0.8037.57 or newer

iOS Chrome 154 is on the App Store (Google posted 154.0.8037.41 on Sept 15; later 154 builds may already be live). Check About in the app.

Printed fake update prompt beside a note to type the address yourself

MFA: YubiKey and Google Authenticator

A hardware key does not install this patch. It does stop a lot of the fake-update phishing that follows a 108-fix headline: a page that looks like Google sign-in, then a “Chrome installer.”

GradeMeaning
FailSMS, email OTP, or no public key / open TOTP
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
Google AccountStrongYesYes
Malwarebytes AccountFailNoNo

Google documents passkeys, Authenticator, and security keys. Chrome sync uses that account. Malwarebytes Account email verification is email OTP (Fail). MFA does not make a sideloaded “Chrome setup” binary safe.

Directory: MFA support directory · Category → Email & Identity.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside an authenticator phone

Independent cybersecurity audits

We audited the official-notes host, the newsletter source, Google’s consumer domain, and the Chrome download portal on September 28, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not mean Chrome 154 failed to ship.

OrganizationDomainOverallvs 100%
Chrome Releases hostgoogleblog.com82%−18
Malwarebytesmalwarebytes.com71%−29
Googlegoogle.com55%−45
Chrome download portalchrome.google.com35%−65
DomainIdentityTransportWebsite
googleblog.com90%15%95%
malwarebytes.com90%45%43%
google.com50%70%37%
chrome.google.com0%45%43%

Audit links: googleblog.com · malwarebytes.com · google.com · chrome.google.com

chrome.google.com Identity 0% is why fake “update Chrome” sites work. Type google.com/chrome or use About Chrome. Do not trust a download button in a newsletter even when the newsletter is real.

Printed domain-audit scores well below the 100 percent ideal

Website stack

Passive homepage + Certificate Transparency probes (September 28, 2026). Versions only.

DomainStack note
google.comCMS undetected; Google Trust Services TLS expires 2026-10-22 (~24 days); HTTP→HTTPS redirect not confirmed on probed hosts
chrome.google.comCMS undetected; HTTP→HTTPS redirect not confirmed on probed hosts
malwarebytes.comWordPress, generator version hidden; Amazon Trust TLS expires 2027-03-19
googleblog.comCMS undetected; Google Trust Services TLS expires 2026-12-11

A short Google leaf date is a certificate calendar note, not a Chrome outage.

Blacklist and lookalikes

Email blacklist checks (public DoH, September 28, 2026): google.com, chrome.google.com, malwarebytes.com, and googleblog.com were clear on mail/domain lists we can query.

Registered lookalikes (BEC profile — not proof this patch cycle used them):

Brand scannedTo reviewLikely ownedBEC staging
google.com3190
malwarebytes.com960
googleblog.com500
LookalikeTechniqueSignal
geoogle.comInsertionNS + A + MX
google.app / .biz / .ioTLD swapRegistered; .ai / .us redirect to Google
maalwarebytes.comInsertionA
malwarebytes.appTLD swapNS + A + MX
googleblog.biz / .info / .ioTLD swapNS only

A chrome.google.com squat pass mostly repeats google.com insertions. Type google.com, google.com/chrome, chromereleases.googleblog.com, and malwarebytes.com. Continuous monitoring: Cybersquat Domain Monitoring.

CourtListener RECAP searches for Chrome 154 and the Critical CVE identifiers did not return a matching patch-cycle docket. Unrelated “Chrome Hearts” trademark suits are a different story.

Sources: Chrome Releases — Stable desktop, Sept 22, 2026 · Chrome for Android 154 · Malwarebytes, Sept 24 · SecurityWeek · PCWorld · TechRepublic · Google passkeys / Authenticator · Malwarebytes Account email verification. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 28, 2026. Domain scores: audit.emailmenow.com only. No exploit PoCs or sample pages in this post.