Last updated: 23 Sep 26 16:31:21 (UTC)
2026-09-23 Chrome (Stable) CVE Report
Source: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html Report generated: 2026-09-23 Total CVEs: 108
Executive Summary
This release contains 108 CVEs across 4 severity levels with a total bounty pool of $18,000.
- Critical: 11
- High: 25
- Medium: 47
- Low: 25
- Bounty-bearing: 5
- External reporters: 25
Vulnerability Type Breakdown
| Type | Count | % of Total |
|---|---|---|
| Other | 68 | 63.0% |
| Use After Free | 23 | 21.3% |
| Out of Bounds | 5 | 4.6% |
| Type Confusion | 4 | 3.7% |
| Race Condition | 4 | 3.7% |
| Inappropriate Implementation | 3 | 2.8% |
| Integer Overflow | 1 | 0.9% |
Component Area Distribution
| Component | Count | % of Total |
|---|---|---|
| XR | 19 | 17.6% |
| DevTools | 9 | 8.3% |
| GPU | 6 | 5.6% |
| Forms | 6 | 5.6% |
| ANGLE (Graphics) | 5 | 4.6% |
| General UI | 5 | 4.6% |
| V8 (JavaScript) | 5 | 4.6% |
| Mobile UI | 5 | 4.6% |
| Input Handling | 4 | 3.7% |
| Navigation | 3 | 2.8% |
| Views UI | 3 | 2.8% |
| WebGL | 2 | 1.9% |
| Extensions API | 2 | 1.9% |
| Browser Core | 2 | 1.9% |
| Tint (Shader Compiler) | 2 | 1.9% |
| Bluetooth | 2 | 1.9% |
| HID API | 2 | 1.9% |
| Other/Uncategorized | 2 | 1.9% |
| Chromoting (Remote Desktop) | 2 | 1.9% |
| Media | 2 | 1.9% |
| NFC | 2 | 1.9% |
| Networking | 2 | 1.9% |
| Password Manager | 2 | 1.9% |
| Fullscreen | 1 | 0.9% |
| Chromecast | 1 | 0.9% |
| Other (12 more) | 19 | 17.6% |
Bounty Analysis
Total bounty pool: $18,000 Bounty-bearing CVEs: 5
| CVE ID | Severity | Description | Bounty |
|---|---|---|---|
| CVE-2026-95350 | Critical | Buffer overflow in ANGLE. | $5000 |
| CVE-2026-95301 | High | Missing authorization in Extensions. | $5000 |
| CVE-2026-95291 | High | UI misrepresentation in SecurityIndicators. | $5000 |
| CVE-2026-95357 | Critical | Out of bounds write in GPU. | $2500 |
| CVE-2026-95307 | Low | UI misrepresentation in ExtensionsMenu. | $500 |
External Researcher Credits
| Researcher | CVEs |
|---|---|
| @bean5oup | CVE-2026-95286, CVE-2026-95344 |
| Andrew Boni | CVE-2026-95339 |
| Anymous | CVE-2026-95357 |
| Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng of STAR Labs SG Pte. LTd. | CVE-2026-95350 |
| David Sievers (@loknop) | CVE-2026-95322 |
| Hafiizh | CVE-2026-95307 |
| HoneyBee | CVE-2026-95365, CVE-2026-95343 |
| Hongwei Li, Zhun Wang, Ziyue Pan, Junmin Zhu, Saastha Vasan, and Wenbo Guo | CVE-2026-95342 |
| Muhammad Alifa Ramdhan (STARLABS SG) | CVE-2026-95284 |
| Muhammad Alifa Ramdhan of STAR Labs SG Pte. Ltd. | CVE-2026-95281 |
| NH DEV | CVE-2026-95291, CVE-2026-95374 |
| OGINOME Tomohito | CVE-2026-95301 |
| OpenAI Codex Security (amyb) | CVE-2026-95304, CVE-2026-95306 |
| Quyền Sơn (@zer0qs1337) | CVE-2026-95296 |
| SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) | CVE-2026-95338 |
| TienPA - NGS Holdings | CVE-2026-95293 |
| Vu Van Tien (@n0_Be3r) | CVE-2026-95289 |
| Wihdatu Nuuro Ahmadi | CVE-2026-95323 |
| WinD39 - Huynh Dinh Vu | CVE-2026-95313, CVE-2026-95335 |
| Xinyang Ge | CVE-2026-95356, CVE-2026-95310, CVE-2026-95351 |
| Zabith Mohammed (@nmzabith) | CVE-2026-95275 |
| a45hif | CVE-2026-95347 |
| alex.laboirie | CVE-2026-95318 |
| jodyritonga | CVE-2026-95321 |
| sean geofrey | CVE-2026-95333 |
Critical & High Severity Analysis
36 CVEs at Critical or High severity.
By vulnerability type:
- Use After Free: 16
- Other: 12
- Out of Bounds: 4
- Type Confusion: 3
- Race Condition: 1
By component:
- GPU: 5
- XR: 5
- ANGLE (Graphics): 3
- V8 (JavaScript): 3
- WebGL: 2
- DevTools: 2
- Views UI: 2
- Other/Uncategorized: 2
- Fullscreen: 1
- Extensions API: 1
Reporting Timeline
| Date | CVEs Reported |
|---|---|
| 2025-06-11 | 1 |
| 2026-03-23 | 1 |
| 2026-03-28 | 3 |
| 2026-03-29 | 1 |
| 2026-03-30 | 1 |
| 2026-04-06 | 1 |
| 2026-04-11 | 1 |
| 2026-04-13 | 3 |
| 2026-05-01 | 1 |
| 2026-05-10 | 1 |
| 2026-05-14 | 3 |
| 2026-05-15 | 1 |
| 2026-05-16 | 3 |
| 2026-05-17 | 5 |
| 2026-05-19 | 2 |
| 2026-05-25 | 1 |
| 2026-05-27 | 2 |
| 2026-05-28 | 4 |
| 2026-05-29 | 3 |
| 2026-06-05 | 2 |
| 2026-06-10 | 3 |
| 2026-06-14 | 2 |
| 2026-06-16 | 1 |
| 2026-06-22 | 1 |
| 2026-07-01 | 1 |
| 2026-07-09 | 5 |
| 2026-07-14 | 1 |
| 2026-07-15 | 1 |
| 2026-07-18 | 1 |
| 2026-07-19 | 1 |
| 2026-07-22 | 1 |
| 2026-07-29 | 1 |
| 2026-08-05 | 1 |
| 2026-08-06 | 1 |
| 2026-08-07 | 2 |
| 2026-08-12 | 1 |
| 2026-08-13 | 1 |
| 2026-08-14 | 2 |
| 2026-08-16 | 1 |
| 2026-08-17 | 1 |
| 2026-08-18 | 2 |
| 2026-08-21 | 2 |
| 2026-08-22 | 1 |
| 2026-08-23 | 1 |
| 2026-08-24 | 3 |
| 2026-08-26 | 8 |
| 2026-08-27 | 3 |
| 2026-08-28 | 1 |
| 2026-08-29 | 1 |
| 2026-09-01 | 1 |
| 2026-09-03 | 4 |
| 2026-09-05 | 1 |
| 2026-09-08 | 1 |
| 2026-09-09 | 1 |
| 2026-09-10 | 1 |
| 2026-09-11 | 1 |
| 2026-09-12 | 4 |
| 2026-09-15 | 1 |
| 2026-09-16 | 2 |
Methodology Notes
- Structured CVE data extracted via
unjam --cve. - Vulnerability types and component areas classified from CVE description text.
- Bounty amounts from the
bountyfield in unjam output. - External researchers identified from the
reporterfield (non-Google, non-anonymous).