Google has released Chrome 154 with fixes for 108 security vulnerabilities across the browser, including 11 issues classified as critical.
The update is focused almost entirely on security rather than new features. There are currently no known reports of the patched vulnerabilities being actively exploited, but the large number of fixes and the presence of multiple critical issues make the update important for Chrome users.
The latest desktop versions are 154.0.8037.57 and 154.0.8037.58 for Windows and macOS, while Linux receives version 154.0.8037.57.
Chrome 154 addresses a wide range of security problems
Of the 108 vulnerabilities fixed in Chrome 154, Google identified 76 internally.
The remaining 32 were reported by external security researchers through the company's vulnerability reward program.
Google has awarded a total of $18,000 in bounties so far for the externally reported issues included in this release.
| Severity | Number of vulnerabilities |
|---|---|
| Critical | 11 |
| High | 25 |
| Medium | 47 |
| Low | 25 |
| Total | 108 |
The 11 critical vulnerabilities make up the most serious group.
Three of those are buffer overflow issues found in ANGLE, the graphics translation layer used by Chrome for WebGL and other rendering tasks.
Buffer overflow vulnerabilities can be particularly serious because they may allow software to read or write memory outside the area originally intended by the application.
The exact impact depends on the individual flaw and how successfully an attacker could exploit it.
Use after free bugs were the most common issue
Use after free vulnerabilities represent the largest single category in the Chrome 154 update.
The browser patches 34 issues of this type.
A use after free flaw can occur when software continues using a memory location after that memory has already been released. Under certain conditions, attackers may be able to manipulate the reused memory and cause unexpected behavior.
Other categories are also heavily represented.
Chrome 154 fixes 12 UI misrepresentation vulnerabilities, 12 incorrect authorization flaws and 11 missing authorization issues.
These bugs affect different parts of browser security, from how information is shown on screen to whether certain operations are correctly permitted or blocked.
No active attacks have been reported
One important detail is that none of the vulnerabilities included in Chrome 154 are currently known to be exploited in active attacks.
That reduces the immediate urgency compared with a zero day vulnerability already being used in the wild.
However, once a security update becomes public, attackers may begin analyzing the patches to understand what was fixed.
That means installing the update quickly is still recommended, particularly when critical and high risk vulnerabilities are involved.
Chrome normally updates automatically, so many installations will receive the new version without manual intervention.
If you want to check manually, open Chrome's menu and go to Help, then About Google Chrome.
The browser will check for available updates and usually ask for a restart once installation is complete.
You can also reach the same update screen through Settings and About Google Chrome.
Android and iOS versions are also being updated
The security release is not limited to desktop systems.
Chrome for Android has been updated to version 154.0.8037.57.
The Android release addresses the same vulnerability set as the desktop edition.
Chrome for iOS has also moved to version 154.0.8037.55 this week.
The exact security architecture differs between Chrome on iOS and other operating systems because Apple's platform uses different browser engine requirements, but the application has still received a corresponding version update.
Google's Extended Stable Channel for Windows and macOS has also been updated, moving to Chromium 152.0.7977.140.
Chrome 154 adds no major new features
Unlike some browser releases, Chrome 154 does not introduce notable new functionality alongside its security work.
Its main purpose is to address vulnerabilities and improve browser safety.

That makes this a maintenance focused release rather than one centered on interface changes, performance features or new user tools.
Chrome 155 is expected in roughly two weeks, continuing Google's rapid browser release schedule.
For now, the main priority is making sure Chrome 154 is installed.
With 108 vulnerabilities fixed, including 11 critical issues and 25 high risk bugs, the update represents a substantial security release even though there is currently no evidence that these flaws are being exploited in attacks.



Discussion (0)
Be the first to comment.