# Chrome Patches Dozens of RCE Flaws

Published: 2026-09-24 · Severity: routine
Canonical: https://vorant.io/reports/b9ee8225-38d4-5e49-aa0f-290597918917/chrome-patches-dozens-of-rce-flaws

> Google Chrome versions before 154.0.8037.57/.58 contain numerous memory-corruption and other bugs that could allow arbitrary code execution; no in-the-wild exploitation reported yet.

MS-ISAC issued an advisory detailing a large batch of vulnerabilities patched in Google Chrome (prior to 154.0.8037.57/.58 for Windows/Mac and 154.0.8037.57 for Linux). The most severe issues are memory-safety bugs — buffer overflows, use-after-free, out-of-bounds writes, and type confusion — spread across core browser components including ANGLE, GPU, V8, WebGL, PDFium, ServiceWorker, Bluetooth, HID, and DevTools. Successful exploitation of the most severe flaws could allow an attacker to achieve arbitrary code execution in the context of the logged-in user, potentially leading to installation of programs, data manipulation, or creation of new accounts, with impact scaled to the privileges of the affected account.

The advisory also lists numerous lower-severity issues such as missing/incorrect authorization checks, UI misrepresentation (spoofing), information leaks, and confused-deputy conditions across features like Navigation, Extensions, Payments, Passwords, and Safebrowsing. These are less likely to yield code execution but could support phishing, privilege escalation, or data exposure. MS-ISAC notes no current reports of in-the-wild exploitation for any of these CVEs.

Defenders should prioritize timely patch deployment via automated update mechanisms, since exploitation is characterized as a drive-by compromise vector (T1189) requiring only that a user visit a malicious or compromised page. Standard hardening measures — least-privilege accounts, browser sandboxing/exploit protection, DNS/URL filtering, and user awareness — reduce the blast radius of any future exploitation attempts targeting these flaws.

## Mentioned in this report

- Vulnerabilities: CVE-2026-95277, CVE-2026-95280, CVE-2026-95281, CVE-2026-95282, CVE-2026-95283, CVE-2026-95284, CVE-2026-95286, CVE-2026-95293, CVE-2026-95298, CVE-2026-95299, CVE-2026-95304, CVE-2026-95306, CVE-2026-95310, CVE-2026-95313, CVE-2026-95315, CVE-2026-95318, CVE-2026-95322, CVE-2026-95324, CVE-2026-95325, CVE-2026-95329, CVE-2026-95331, CVE-2026-95335, CVE-2026-95338, CVE-2026-95339, CVE-2026-95343, CVE-2026-95345, CVE-2026-95348, CVE-2026-95349, CVE-2026-95350, CVE-2026-95351, CVE-2026-95353, CVE-2026-95354, CVE-2026-95356, CVE-2026-95357, CVE-2026-95359, CVE-2026-95365, CVE-2026-95366, CVE-2026-95372, CVE-2026-95373, CVE-2026-95380

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-101

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b9ee8225-38d4-5e49-aa0f-290597918917/chrome-patches-dozens-of-rce-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
