CERT-In Vulnerability Note
CIVN-2026-0484
Multiple Vulnerabilities in Google Chrome for Desktop
Original Issue Date:September 30, 2026
Severity Rating: HIGH
Software Affected
- Google Chrome prior to 154.0.8037.57/.58 for Windows and Mac
- Google Chrome prior to 154.0.8037.57 Linux
Overview
Multiple vulnerabilities have been reported in Google chrome for Desktop which could allow a remote attacker to execute arbitrary code, obtain sensitive information, perform spoofing attack, bypass security restrictions or cause denial of service (DoS) conditions on the targeted system.
Target Audience: All end-user organizations and individuals using affected version of Google Chrome for Desktop.
Risk Assessment: High risk of remote code execution and bypass security restrictions.
Impact Assessment: Potential for remote code execution, denial of service (DoS), unauthorized access to sensitive data, and complete system compromise.
Description
Google Chrome is a popular internet browser used for accessing information on the World Wide Web. It is designed for use on desktop systems including Windows, macOS and Linux.
Multiple vulnerabilities have been reported in Google Chrome for Desktop due to Buffer overflow in ANGLE, WebGL,Video,Tint; Out of bounds write in GPU,WebGL, V8, ANGLE; Use after free in ServiceWorker, Fullscreen, WindowDialog, AdFilter, Platform, DevTools, Views, Bluetooth, HID, PDFium, Aura, Browser, Chromecast, WebAudio, GPU, Actor, Bindings, Verifier, ANGLE, Updater, Metrics, Printing; Missing authorization in Extensions, Navigation, Contextual Tasks, Views, NFC, DevTools, Chromium, WebView, WakeLock, V8, Core; UI misrepresentation in SecurityIndicators, Browser, Messages, Chromoting, FileSystem, Payments, ExtensionsMenu, Omnibox, Mobile; Incorrect authorization in Navigation, BrowserTag, WebAPKs, MediaCapture, HID, Network, Scroll, Mobile, Safebrowsing, DevTools, PictureInPicture; Uninitialized resource in GPU; Improper output encoding in DevTools; Type confusion in Bindings, IndexedDB, V8; Race condition in V8, Editing, Transactions Platform, DevTools; Use of released resource in Core; Improper input validation in Auth, Printing, Themes, Desktop, Passwords; Cross-site request forgery in DevTools; Inappropriate implementation in XML, NFC, PlatformIntegration; Externally controlled reference in DevTools; Improper state validation in Downloads; Incomplete cleanup in SmartCard, Bluetooth; Information leak in Mobile, Transactions Platform, Passwords, Networking, DataTransfer; Incorrect reference resolution in MediaStream, WebProtect; Use of uninitialized variable in Tint; Free of non-heap memory in Fonts; Integer overflow in Metrics; Unchecked return value in Performance and Confused deputy in Mobile. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, obtain sensitive information, perform spoofing attack, bypass security restrictions or cause denial of service (DoS) conditions on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html
References
Google Chrome
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html
CVE Name
CVE-2026-95274
CVE-2026-95275
CVE-2026-95276
CVE-2026-95277
CVE-2026-95278
CVE-2026-95279
CVE-2026-95280
CVE-2026-95281
CVE-2026-95282
CVE-2026-95283
CVE-2026-95284
CVE-2026-95285
CVE-2026-95286
CVE-2026-95287
CVE-2026-95288
CVE-2026-95289
CVE-2026-95290
CVE-2026-95291
CVE-2026-95292
CVE-2026-95293
CVE-2026-95294
CVE-2026-95295
CVE-2026-95296
CVE-2026-95297
CVE-2026-95298
CVE-2026-95299
CVE-2026-95300
CVE-2026-95301
CVE-2026-95302
CVE-2026-95303
CVE-2026-95304
CVE-2026-95305
CVE-2026-95306
CVE-2026-95307
CVE-2026-95308
CVE-2026-95309
CVE-2026-95310
CVE-2026-95311
CVE-2026-95312
CVE-2026-95313
CVE-2026-95314
CVE-2026-95315
CVE-2026-95316
CVE-2026-95317
CVE-2026-95318
CVE-2026-95319
CVE-2026-95320
CVE-2026-95321
CVE-2026-95322
CVE-2026-95323
CVE-2026-95324
CVE-2026-95325
CVE-2026-95326
CVE-2026-95327
CVE-2026-95328
CVE-2026-95329
CVE-2026-95330
CVE-2026-95331
CVE-2026-95332
CVE-2026-95333
CVE-2026-95334
CVE-2026-95335
CVE-2026-95336
CVE-2026-95337
CVE-2026-95338
CVE-2026-95339
CVE-2026-95340
CVE-2026-95341
CVE-2026-95342
CVE-2026-95343
CVE-2026-95344
CVE-2026-95345
CVE-2026-95346
CVE-2026-95347
CVE-2026-95348
CVE-2026-95349
CVE-2026-95350
CVE-2026-95351
CVE-2026-95352
CVE-2026-95353
CVE-2026-95354
CVE-2026-95355
CVE-2026-95356
CVE-2026-95357
CVE-2026-95358
CVE-2026-95359
CVE-2026-95360
CVE-2026-95361
CVE-2026-95362
CVE-2026-95363
CVE-2026-95364
CVE-2026-95365
CVE-2026-95366
CVE-2026-95367
CVE-2026-95368
CVE-2026-95369
CVE-2026-95370
CVE-2026-95371
CVE-2026-95372
CVE-2026-95373
CVE-2026-95374
CVE-2026-95375
CVE-2026-95376
CVE-2026-95380
CVE-2026-95381
CVE-2026-95382
CVE-2026-95384
CVE-2026-95385
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|