Security NEXT•September 30, 2026•🇯🇵Translated from Japanese

Google Releases Chrome Security Update Fixing 32 Vulnerabilities Including One Critical Flaw

Google has released a security update for the Chrome web browser that resolves 32 vulnerabilities, including one rated Critical. The company published the patches on September 29, 2026, for Windows and macOS as versions 154.0.8037.93 and 154.0.8037.92, and for Linux as version 154.0.8037.92. The update will be rolled out gradually over the next several days to weeks.

The single Critical vulnerability is CVE-2026-102331, a buffer overflow in the ANGLE graphics processing component. It was reported by an external security researcher on August 24.

Twenty-five vulnerabilities are rated High. These include multiple type confusion and buffer overflow issues in the V8 JavaScript engine, use-after-free flaws in Bluetooth, Views, Passwords, FullScreen, and PictureInPicture, as well as improper handling of uninitialized resources in GPU and WebGPU. Additional High-severity problems cover out-of-bounds writes in GPU, out-of-bounds reads in WebGL, cross-site scripting in WebUI, UI display issues in Omnibox, and permission management weaknesses in Mojo.

One vulnerability is rated Medium and five are rated Low. The full list of addressed CVEs is:

  • CVE-2026-102331 (Critical)
  • CVE-2026-102299 (High)
  • CVE-2026-102300 (High)
  • CVE-2026-102301 (High)
  • CVE-2026-102302 (High)
  • CVE-2026-102303 (High)
  • CVE-2026-102304 (High)
  • CVE-2026-102306 (High)
  • CVE-2026-102307 (High)
  • CVE-2026-102308 (High)
  • CVE-2026-102309 (High)
  • CVE-2026-102311 (High)
  • CVE-2026-102312 (High)
  • CVE-2026-102313 (High)
  • CVE-2026-102315 (High)
  • CVE-2026-102316 (High)
  • CVE-2026-102317 (High)
  • CVE-2026-102318 (High)
  • CVE-2026-102319 (High)
  • CVE-2026-102321 (High)
  • CVE-2026-102323 (High)
  • CVE-2026-102324 (High)
  • CVE-2026-102325 (High)
  • CVE-2026-102326 (High)
  • CVE-2026-102328 (High)
  • CVE-2026-102329 (High)
  • CVE-2026-102320 (Medium)
  • CVE-2026-102305 (Low)
  • CVE-2026-102310 (Low)
  • CVE-2026-102314 (Low)
  • CVE-2026-102327 (Low)
  • CVE-2026-102330 (Low)

Related articles

Habr•Vulnerabilities & Exploits

Recon in Bug Bounty: Spotting Anomalies Instead of Chasing Known Vulnerability Patterns

The article explains that effective reconnaissance in Bug Bounty programs goes far beyond automated subdomain enumeration with tools like subfinder or httpx. It emphasizes building a mental model of the target application by analyzing policy documents, infrastructure changes via Censys and Shodan, and identifying behavioral anomalies rather than matching textbook vulnerability patterns. A detailed case study describes how a hidden legacy endpoint on ibm.com was discovered during passive and active reconnaissance, leading to the identification of a time-based Blind SQL Injection vulnerability confirmed with sqlmap. The author stresses that recon is a continuous process involving hypothesis testing, understanding service trust boundaries, and evaluating real security impact for triage teams. Practical advice includes reviewing HackerOne reports for context, maintaining motivation through interesting targets, and revisiting programs as infrastructure evolves. The piece also covers how JavaScript analysis and direct endpoint interaction help map authorization flows and weak links between microservices.

Hispasec•Vulnerabilities & Exploits

Automated Scans Exploit CVE-2026-39364 in Exposed Vite Dev Servers to Steal AWS and Azure Secrets

A large-scale automated campaign is actively scanning the internet for publicly exposed Vite development servers to exfiltrate sensitive files and cloud credentials. Attackers leverage CVE-2026-39364 to bypass server.fs.deny restrictions and read arbitrary files using crafted query parameters such as ?raw combined with ?import. The campaign has generated thousands of requests over several weeks, with telemetry from honeypots recording 807 sessions and roughly 32,000 events in a single month. Targets include .env files, terraform.tfstate, and other infrastructure-as-code artifacts that often contain AWS access keys and Microsoft Azure tokens. The vulnerable versions are Vite 7.1.0 through versions prior to 7.3.2 and Vite 8.x prior to 8.0.5. Part of the scanning traffic originates from Google Cloud IP ranges 34.x and 35.x. Organizations are urged to update immediately, restrict the dev server to localhost, and rotate any exposed cloud credentials.

Habr•Vulnerabilities & Exploits

cKEV Index Launches to Prioritize Vulnerabilities Using Urgent Patch Score Methodology

CyberOK has introduced the open cKEV Index, a catalog of high-priority vulnerabilities based on the Urgent Patch Score (UPS) framework that tracks signals such as exploit publication and confirmed attacks. The index addresses the growing gap between accelerated vulnerability discovery powered by AI and the slower pace of patching, testing, and deployment in real environments. It incorporates timelines from sources including Anthropic reports on AI-assisted campaigns GTG-50014 and GTG-50029, the rust-in-peace framework, Microsoft Exchange Server Subscription Edition delays, and Oracle’s record 1,434 CVE fixes. UPS defines progressive phases from Radar to Emergency/IR, allowing teams to link specific events like PoC releases or CISA KEV additions to concrete actions under resource constraints. Research using 2025 CISA KEV data shows that early signals enable 35–53% of patches to be completed before official exploitation confirmation. The public version displays only Urgent Patch and Emergency stages with event histories, while full data and API access are available to CyberOK customers.

Security NEXT•Vulnerabilities & Exploits

Multiple Vulnerabilities Found in WatchGuard Access Points Including Critical Flaw

WatchGuard Technologies has disclosed three vulnerabilities affecting its WatchGuard AP access point products, one of which is rated critical. The issues were detailed in an advisory published on September 28 and involve flaws in internal API services and a diagnostic command-line interface. CVE-2026-86102 allows OS command injection that can lead to arbitrary shell command execution on the underlying operating system when an attacker has network access. CVE-2026-101891 stems from improper access controls that permit unauthenticated acquisition of valid API sessions. CVE-2026-87969 affects the diagnostic CLI and enables arbitrary OS command execution but requires administrator privileges to exploit. The findings were reported by Security NEXT.