VORANT. Threat Intelligence Research Sign in Create a free account

Chrome Patches Dozens of RCE Flaws

routine vulnerability

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Google Chrome versions before 154.0.8037.57/.58 contain numerous memory-corruption and other bugs that could allow arbitrary code execution; no in-the-wild exploitation reported yet.

MS-ISAC issued an advisory detailing a large batch of vulnerabilities patched in Google Chrome (prior to 154.0.8037.57/.58 for Windows/Mac and 154.0.8037.57 for Linux). The most severe issues are memory-safety bugs — buffer overflows, use-after-free, out-of-bounds writes, and type confusion — spread across core browser components including ANGLE, GPU, V8, WebGL, PDFium, ServiceWorker, Bluetooth, HID, and DevTools. Successful exploitation of the most severe flaws could allow an attacker to achieve arbitrary code execution in the context of the logged-in user, potentially leading to installation of programs, data manipulation, or creation of new accounts, with impact scaled to the privileges of the affected account.

The advisory also lists numerous lower-severity issues such as missing/incorrect authorization checks, UI misrepresentation (spoofing), information leaks, and confused-deputy conditions across features like Navigation, Extensions, Payments, Passwords, and Safebrowsing. These are less likely to yield code execution but could support phishing, privilege escalation, or data exposure. MS-ISAC notes no current reports of in-the-wild exploitation for any of these CVEs.

Defenders should prioritize timely patch deployment via automated update mechanisms, since exploitation is characterized as a drive-by compromise vector (T1189) requiring only that a user visit a malicious or compromised page. Standard hardening measures — least-privilege accounts, browser sandboxing/exploit protection, DNS/URL filtering, and user awareness — reduce the blast radius of any future exploitation attempts targeting these flaws.

Mentioned in this report

Vulnerabilities CVE-2026-95277CVE-2026-95280CVE-2026-95281CVE-2026-95282CVE-2026-95283CVE-2026-95284CVE-2026-95286CVE-2026-95293CVE-2026-95298CVE-2026-95299CVE-2026-95304CVE-2026-95306CVE-2026-95310CVE-2026-95313CVE-2026-95315CVE-2026-95318CVE-2026-95322CVE-2026-95324CVE-2026-95325CVE-2026-95329CVE-2026-95331CVE-2026-95335CVE-2026-95338CVE-2026-95339CVE-2026-95343CVE-2026-95345CVE-2026-95348CVE-2026-95349CVE-2026-95350CVE-2026-95351CVE-2026-95353CVE-2026-95354CVE-2026-95356CVE-2026-95357CVE-2026-95359CVE-2026-95365CVE-2026-95366CVE-2026-95372CVE-2026-95373CVE-2026-95380

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-101

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 9,821 reports from 151 sources, 1,544 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs