Chrome update fixes two bugs that can escape the sandbox

Published

Google has released another security update for Chrome desktop, fixing 11 vulnerabilities in a single point release. Two of them carry a CVSS score of 9.6, and both, according to their published descriptions, could let an attacker run code outside the browser's sandbox, the isolation layer that is supposed to stop a malicious web page from touching the rest of the computer.

The fixed builds are Chrome 154.0.8037.97 for Linux and 154.0.8037.97/.98 for Mac and Windows. Google announced the release on its Chrome Releases blog, and Hong Kong's computer emergency response team, HKCERT, summarised it in a security bulletin rating the overall risk as medium. Neither source reports any of the flaws being exploited in the wild.

Two bugs reach past the sandbox

The more serious of the pair is CVE-2026-103628, an out-of-bounds write in WebGL, the component that lets web pages draw 3D graphics. An out-of-bounds write means the browser writes data past the edge of the memory it was given. The public CVE record says a remote attacker could use it to execute arbitrary code outside the sandbox through a crafted HTML page, and Chromium's own team rates it Critical.

The second is CVE-2026-103626, an incorrect authorization flaw in Chrome's FileSystem component that affects Windows only. Its record says an attacker could potentially execute code outside the sandbox via a crafted page, but only by leveraging social engineering, meaning the victim has to be talked into doing something first. Chromium rates that one High, while the CVE record scores it 9.6.

The remaining nine fixes (CVE-2026-103621 to CVE-2026-103625, CVE-2026-103627 and CVE-2026-103629 to CVE-2026-103631) have no published severity score in the sources available at the time of writing. HKCERT groups the possible impacts of the whole set as remote code execution, denial of service, security restriction bypass and information disclosure, and Google's release notes carry the per-bug detail.

Restart Chrome on 154.0.8037.97 or later

Chrome normally updates itself in the background, but the fix only takes effect once the browser restarts. Users can force the check from the About Google Chrome page in settings, and administrators managing fleets should confirm endpoints have moved to 154.0.8037.97 (Linux) or 154.0.8037.97/.98 (Mac and Windows) or later. Other Chromium-based browsers typically ship the same fixes in their own releases, so check those vendors' update channels too.

This is the latest in a run of Chrome 154 security releases, following the build that fixed 11 critical bugs, most of them in graphics code, and the same-day Chrome and Firefox patch drop at the end of September. Graphics code keeps turning up in these lists for a reason: it is large, fast-moving and handed attacker-controlled input by every page a user visits, which makes a prompt restart the cheapest defence available.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions