Severity: CriticalAction: Patch
Stable Channel Update for ChromeOS / ChromeOS Flex
Patch
Apply the vendor's security update for Android and Chrome.
Official fix available since
Apply the vendor's update to every affected system. Check the fixed-in versions below where known.
Basis: Google Chrome Releases vendor advisory
Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
| Product | Vendor | Affected versions | Fixed in | Source |
|---|---|---|---|---|
| Chrome | < 154.0.8037.57 | 154.0.8037.57 | NVD |
Sources: NVD = NIST National Vulnerability Database.
Developments from the last 30 days, newest first.
CVE-2026-95304 scored CVSS 8.8
Basis: NIST National Vulnerability Database
Apply the vendor's security update for Android and Chrome.