Last updated: 23 Sep 26 16:31:21 (UTC)

2026-09-23 Chrome (Stable) CVE Report

Source: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html Report generated: 2026-09-23 Total CVEs: 108

Executive Summary

This release contains 108 CVEs across 4 severity levels with a total bounty pool of $18,000.

  • Critical: 11
  • High: 25
  • Medium: 47
  • Low: 25
  • Bounty-bearing: 5
  • External reporters: 25

Vulnerability Type Breakdown

Type Count % of Total
Other 68 63.0%
Use After Free 23 21.3%
Out of Bounds 5 4.6%
Type Confusion 4 3.7%
Race Condition 4 3.7%
Inappropriate Implementation 3 2.8%
Integer Overflow 1 0.9%

Component Area Distribution

Component Count % of Total
XR 19 17.6%
DevTools 9 8.3%
GPU 6 5.6%
Forms 6 5.6%
ANGLE (Graphics) 5 4.6%
General UI 5 4.6%
V8 (JavaScript) 5 4.6%
Mobile UI 5 4.6%
Input Handling 4 3.7%
Navigation 3 2.8%
Views UI 3 2.8%
WebGL 2 1.9%
Extensions API 2 1.9%
Browser Core 2 1.9%
Tint (Shader Compiler) 2 1.9%
Bluetooth 2 1.9%
HID API 2 1.9%
Other/Uncategorized 2 1.9%
Chromoting (Remote Desktop) 2 1.9%
Media 2 1.9%
NFC 2 1.9%
Networking 2 1.9%
Password Manager 2 1.9%
Fullscreen 1 0.9%
Chromecast 1 0.9%
Other (12 more) 19 17.6%

Bounty Analysis

Total bounty pool: $18,000 Bounty-bearing CVEs: 5

CVE ID Severity Description Bounty
CVE-2026-95350 Critical Buffer overflow in ANGLE. $5000
CVE-2026-95301 High Missing authorization in Extensions. $5000
CVE-2026-95291 High UI misrepresentation in SecurityIndicators. $5000
CVE-2026-95357 Critical Out of bounds write in GPU. $2500
CVE-2026-95307 Low UI misrepresentation in ExtensionsMenu. $500

External Researcher Credits

Researcher CVEs
@bean5oup CVE-2026-95286, CVE-2026-95344
Andrew Boni CVE-2026-95339
Anymous CVE-2026-95357
Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng of STAR Labs SG Pte. LTd. CVE-2026-95350
David Sievers (@loknop) CVE-2026-95322
Hafiizh CVE-2026-95307
HoneyBee CVE-2026-95365, CVE-2026-95343
Hongwei Li, Zhun Wang, Ziyue Pan, Junmin Zhu, Saastha Vasan, and Wenbo Guo CVE-2026-95342
Muhammad Alifa Ramdhan (STARLABS SG) CVE-2026-95284
Muhammad Alifa Ramdhan of STAR Labs SG Pte. Ltd. CVE-2026-95281
NH DEV CVE-2026-95291, CVE-2026-95374
OGINOME Tomohito CVE-2026-95301
OpenAI Codex Security (amyb) CVE-2026-95304, CVE-2026-95306
Quyền Sơn (@zer0qs1337) CVE-2026-95296
SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) CVE-2026-95338
TienPA - NGS Holdings CVE-2026-95293
Vu Van Tien (@n0_Be3r) CVE-2026-95289
Wihdatu Nuuro Ahmadi CVE-2026-95323
WinD39 - Huynh Dinh Vu CVE-2026-95313, CVE-2026-95335
Xinyang Ge CVE-2026-95356, CVE-2026-95310, CVE-2026-95351
Zabith Mohammed (@nmzabith) CVE-2026-95275
a45hif CVE-2026-95347
alex.laboirie CVE-2026-95318
jodyritonga CVE-2026-95321
sean geofrey CVE-2026-95333

Critical & High Severity Analysis

36 CVEs at Critical or High severity.

By vulnerability type:

  • Use After Free: 16
  • Other: 12
  • Out of Bounds: 4
  • Type Confusion: 3
  • Race Condition: 1

By component:

  • GPU: 5
  • XR: 5
  • ANGLE (Graphics): 3
  • V8 (JavaScript): 3
  • WebGL: 2
  • DevTools: 2
  • Views UI: 2
  • Other/Uncategorized: 2
  • Fullscreen: 1
  • Extensions API: 1

Reporting Timeline

Date CVEs Reported
2025-06-11 1
2026-03-23 1
2026-03-28 3
2026-03-29 1
2026-03-30 1
2026-04-06 1
2026-04-11 1
2026-04-13 3
2026-05-01 1
2026-05-10 1
2026-05-14 3
2026-05-15 1
2026-05-16 3
2026-05-17 5
2026-05-19 2
2026-05-25 1
2026-05-27 2
2026-05-28 4
2026-05-29 3
2026-06-05 2
2026-06-10 3
2026-06-14 2
2026-06-16 1
2026-06-22 1
2026-07-01 1
2026-07-09 5
2026-07-14 1
2026-07-15 1
2026-07-18 1
2026-07-19 1
2026-07-22 1
2026-07-29 1
2026-08-05 1
2026-08-06 1
2026-08-07 2
2026-08-12 1
2026-08-13 1
2026-08-14 2
2026-08-16 1
2026-08-17 1
2026-08-18 2
2026-08-21 2
2026-08-22 1
2026-08-23 1
2026-08-24 3
2026-08-26 8
2026-08-27 3
2026-08-28 1
2026-08-29 1
2026-09-01 1
2026-09-03 4
2026-09-05 1
2026-09-08 1
2026-09-09 1
2026-09-10 1
2026-09-11 1
2026-09-12 4
2026-09-15 1
2026-09-16 2

Methodology Notes

  • Structured CVE data extracted via unjam --cve.
  • Vulnerability types and component areas classified from CVE description text.
  • Bounty amounts from the bounty field in unjam output.
  • External researchers identified from the reporter field (non-Google, non-anonymous).