Securityweek Critical Chrome Update Addresses 33 Security Flaws Including CVE-2026-102331
Article Content
- •Google's Chrome update addresses 33 vulnerabilities, including CVE-2026-102331.
- •CVE-2026-102331 is a critical buffer overflow flaw with a CVSS score of 9.6.
- •Users are advised to update their browsers immediately to mitigate risks.
On September 29, 2026, Google released a Chrome update addressing 33 security vulnerabilities, including a critical buffer overflow flaw in ANGLE, tracked as CVE-2026-102331. This update affects Chrome versions 154.0.8037.92/.93 for Windows and macOS, and 154.0.8037.92 for Linux. The critical flaw, reported by an external researcher, poses a significant risk due to its potential for exploitation. Additionally, the update includes fixes for several high-severity vulnerabilities, particularly in the V8 JavaScript engine, which include type confusion and use-after-free issues. Users are urged to update their browsers promptly to mitigate risks. Mozilla also released a Firefox update addressing 76 vulnerabilities, but no exploitation in the wild has been reported for either browser. The updates are part of ongoing efforts to enhance browser security and protect users from potential threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Star Blizzard and CVE-2026-102299 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Star Blizzard Expands Phishing Operations with RedFlick Technique Russian state-sponsored hacking group Star Blizzard has significantly escalated its phishing operations since January 2026, targeting over 100 organizations, primarily in the U.S. and U.K. The group has shifted from targeted spear-phishing to large-scale campaigns, employing a new malware delivery method called…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…