Google Releases Chrome Update Fixing 11 Vulnerabilities Including Critical WebGL Flaw
Google has released an update for its Chrome web browser that resolves 11 security vulnerabilities. The company issued the patches on October 1, 2026, providing Chrome 154.0.8037.98 and Chrome 154.0.8037.97 for Windows and macOS, and Chrome 154.0.8037.97 for Linux.
The update addresses 11 vulnerabilities tracked by CVE identifiers. One issue received the highest severity rating of Critical: CVE-2026-103628, an out-of-bounds memory write vulnerability in WebGL that Google had reported in August.
Nine vulnerabilities were rated High. These include improper authorization in FileSystem, integer overflows in Compositing and Skia, and use-after-free issues in FedCM, Contextual Tasks, SVG, and MediaStream. The update also fixes a buffer overflow in WebRTC tracked as CVE-2026-103631, reported by Anthropic researcher Xinyang Ge with assistance from Claude.
Additional fixes cover a type confusion flaw in the V8 scripting engine and one Medium-severity vulnerability. Google will deploy the update gradually over the next several days to weeks.
The complete list of addressed CVEs is:
- CVE-2026-103628 (Critical)
- CVE-2026-103621 (High)
- CVE-2026-103622 (High)
- CVE-2026-103623 (High)
- CVE-2026-103624 (High)
- CVE-2026-103625 (High)
- CVE-2026-103626 (High)
- CVE-2026-103629 (High)
- CVE-2026-103630 (High)
- CVE-2026-103631 (High)
- CVE-2026-103627 (Medium)
Related articles
Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings
Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.
Browser Built on Mistakes: How Real-World Attacks Shaped Modern Browser Defenses
Browser security features such as process isolation, sandboxing, and restrictions on code execution were not designed in isolation but evolved directly in response to concrete attacks over more than a decade. Early threats like malicious Flash advertisements in 2015 demonstrated how a single compromised banner could compromise an entire system, prompting the industry to phase out plugins entirely. Later discoveries, including the Spectre vulnerability, forced browsers to implement stricter site isolation and timing-attack mitigations that remain in place today. Session hijacking and malicious browser extensions further drove the adoption of stronger cookie protections and permission models. BI.ZONE analysts trace this history through specific incidents to show why current architectures prioritize separation of sites into distinct processes. The resulting design reduces the blast radius of any single exploit and continues to adapt as new attack classes emerge.
cKEV Index Launches to Prioritize Vulnerabilities as AI Accelerates Exploit Development
CyberOK has introduced the open cKEV Index, a catalog of high-priority vulnerabilities ranked by the Urgent Patch Score (UPS) methodology. The index incorporates timelines of events such as exploit publication, proof-of-concept releases, and confirmed attacks to help organizations prioritize patching under resource constraints. It addresses the growing gap between rapid AI-assisted vulnerability discovery and slower remediation processes at both vendors and customers. Examples from Anthropic reports highlight how threat actors used AI agents for reconnaissance, code analysis, and exploit development against Android apps and web applications. Microsoft and Oracle have publicly linked increased vulnerability findings and larger patch releases to AI tooling. The UPS framework defines progressive phases from Radar to Emergency/IR, allowing teams to act on strong signals without waiting for full confirmation. An open version of the catalog is now available with detailed event histories for Urgent Patch and Emergency stages.
Apache HTTP Server 2.4.69 Patches 20 Vulnerabilities Including CVSS 9.8 Issues
The Apache HTTP Server development team released version 2.4.69 on October 1, 2026, addressing a total of 20 vulnerabilities. While the Apache Security Team assessed most issues as moderate or low in impact, several vulnerabilities received CVSS base scores as high as 9.8. The update includes fixes for stack-based buffer overflows, use-after-free conditions, and out-of-bounds writes affecting multiple modules. No vulnerabilities were rated Critical or Important by the developers, with five classified as Moderate and fifteen as Low. Specific fixes cover the mod_vhost_alias, mod_http2, mod_dav, and mod_dav_fs modules, along with Windows-specific path handling problems.