Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Google Patches 32 Chrome Flaws Including a Critical Memory-Corruption Bug — Update Now
Google Patches 32 Chrome Flaws Including a Critical Memory-Corruption Bug — Update Now
Read Time:3 Minute, 26 Second

Google has pushed out a new Chrome Stable release that patches 32 security vulnerabilities spanning Windows, macOS, and Linux, among them one critical-severity bug and a long list of high-severity issues touching core browser components. The update is rolling out as version 154.0.8037.92/.93 for Windows and Mac, and 154.0.8037.92 for Linux, with Google saying full distribution will continue over the coming days and weeks.

A Critical Flaw in Chrome’s Graphics Layer

The most serious issue Google addressed, CVE-2026-102331, is a critical buffer overflow in ANGLE, the graphics abstraction layer Chrome uses to translate rendering calls across different operating systems and hardware. A buffer overflow of this kind can corrupt memory in ways that potentially allow an attacker to run arbitrary code inside the browser simply by getting a victim to load a malicious page.

Multiple High-Severity Bugs in the V8 JavaScript Engine

Alongside the critical fix, Google patched a cluster of high-severity vulnerabilities in V8, the engine that executes JavaScript on every website Chrome visits. Several of these — tracked as CVE-2026-102299, CVE-2026-102323, CVE-2026-102326, CVE-2026-102328, and CVE-2026-102321 — are type confusion flaws, a class of bug that occurs when the browser mishandles an object as though it were a different data type than it actually is. Type confusion issues are a favorite target for exploit developers because they frequently lead to memory corruption that can be escalated into full code execution.

Google also fixed CVE-2026-102302, a high-severity buffer overflow elsewhere in V8. Because the engine processes JavaScript served by essentially every website a user visits, a flaw here gives an attacker a direct line to crash the browser — or worse — simply by luring a target to a booby-trapped page.

Use-After-Free Issues Across Several Components

The update also cleans up a batch of memory-safety problems in GPU handling, WebGPU, WebGL, the Dawn graphics library, the Skia rendering engine, Media, Bluetooth, the Views UI framework, the Passwords manager, Fullscreen mode, and Picture-in-Picture. Several of these — in Bluetooth, Views, Passwords, Fullscreen, and Picture-in-Picture — are use-after-free bugs, which happen when a program keeps using a block of memory after it has already been freed. On their own, use-after-free flaws can crash a browser; chained with other weaknesses, they’re a well-known route to remote code execution.

Cross-Site Scripting and Authorization Gaps

Google also closed CVE-2026-102329, a high-severity cross-site scripting vulnerability affecting Chrome’s internal WebUI pages. Bugs in this category let attackers inject scripts into interfaces the browser itself treats as trusted, which can be abused to leak sensitive data or quietly alter browser settings.

Rounding out the fix list are an improper privilege-management issue in Mojo (Chrome’s inter-process communication system), missing authorization checks affecting CORS and the Payments feature, incorrect authorization logic in WebView and Site Isolation, and several UI-spoofing weaknesses in the Omnibox address bar, the TabStrip, and the Sign-In flow — the kind of bugs that can be used to make a fake page look more convincing.

Why Some Details Are Being Withheld

As is standard practice, Google is withholding in-depth technical details for several of the patched bugs until the update has reached the majority of Chrome’s user base. The goal is to buy time for people to patch before proof-of-concept exploits can be reverse-engineered from the fix itself.

What Users Should Do

Given the mix of a critical memory-corruption bug and numerous high-severity issues that are remotely triggerable by nothing more than visiting a malicious webpage, users should not wait for Chrome’s automatic update to run in the background. To check manually:

  • Open Chrome’s menu and go to Help, then “About Google Chrome”
  • Let Chrome check for the latest version and download it
  • Relaunch the browser when prompted to complete the update

The same underlying Chromium codebase powers several other browsers, so users of Chromium-based alternatives should also watch for equivalent updates from their vendor.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Google Patches 32 Chrome Flaws Including a Critical Memory-Corruption Bug — Update Now, use the discussion on Forum.

>> forum community

Comments

Leave a Reply