A week after 108 fixes, Chrome shipped 32 more, and one of them is the serious kind
Chrome updates blur together after a while. This one is worth pulling out of the stream. On 29 September Google pushed 154.0.8037.92 and .93 to Windows and Mac, seven days after the release that closed 108 holes, and one of the 32 fixes in it is rated critical.
CVE-2026-102331 is a buffer overflow in ANGLE, the layer that translates what a web page asks for into something your graphics card understands. It scores 9.6 out of 10, and the reason sits in one phrase of the description: a crafted page could run code outside the sandbox. The sandbox is the box Chrome keeps web pages in, so that a bad page ruins a tab and nothing more. Getting out of it means reaching the rest of the machine. A researcher going by mfx reported the bug in late August, and Google is holding back the technical details until most people have the patch.
The other 31 are quieter. Twenty-five are rated high, spread across the V8 JavaScript engine, WebGPU, WebGL, Mojo, Bluetooth and the password manager, and four of the V8 ones are type confusion bugs, which matter because V8 runs on practically every page you open. Google says none of them are known to have been used against anyone.
Updating is three clicks: menu, Help, About Google Chrome. Chrome fetches the new version on its own but will not swap out the copy that is running until you relaunch, so if you are the sort of person who never actually closes the browser, you may have been a month behind without knowing. Edge sits on the same engine and Microsoft shipped 154.0.4258.48 the same day. Tendvane can push both through winget alongside whatever else on the PC has fallen behind.