Tendvane

← All articles

SecuritySeptember 24, 2026

Chrome 154 closes 108 holes, and not one of them was being used

A hundred and eight security holes, eleven of them critical, and no sign that any of them had been used against anyone. That is Chrome 154, and it is the kind of release people skip.

Google promoted it to the stable channel on 22 September. The builds are 154.0.8037.57 and .58 for Windows and Mac, and .57 for Linux. The full count comes to 11 critical, 25 high, 47 medium and 25 low. Most of the critical ones sit in the parts of the browser that draw the page: three buffer overflows in the ANGLE graphics layer, another in WebGL, two out-of-bounds writes in the GPU code. The remainder are use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog and AdFilter. Outside researchers reported 32 of the 108 and have been paid $18,000 so far. Google's own people found the rest.

"Not exploited yet" describes a moment, not a state of affairs. Once a fix ships, the code change is public, and working out what it repairs is a job somebody will do. The gap between a Chrome release and the first attacks built from it has been closing for years.

There is a practical wrinkle. Chrome 154 rolls out in stages over days and sometimes weeks, so your copy may still be on 153, and a browser you have left open since last week is running whatever it loaded then no matter what version it has downloaded. Open the menu, pick Help, then About Google Chrome. It checks, it downloads, and it shows you a Relaunch button. The relaunch is the part that matters. Tendvane's health score takes note of software left sitting on old versions, which is how a browser quietly ends up three releases behind.

Sources

Download Tendvane