Stable Channel Update for ChromeOS / ChromeOS Flex
Summary
The Stable channel is being updated to OS version 16805.33.0 (Browser version 154.0.8037.151) for most ChromeOS devices. If you find new issues, please let us know one of the following ways File a bug Visit our ChromeOS communities General: Chromebook Help Community Beta Specific: ChromeOS Beta Help Community Report an issue or send feedback on Chrome Interested in switching channels? Find out how . Alon Bajayo, Google ChromeOS ChromeOS Vulnerability Rewards Program Reported Bug Fixes: N/A Other 3rd Party Security Fixes Included: High Fixes mali_kbase: use-after-free write in delete_hoarded_chunks allows GPU-process to kernel memory corruption High Fixes Potential StartArcVm unvalidated wayland_server field leads to crosvm sandbox weakening Android Security fixes can be found here Chrome Browser Security Fixes: [$TBD] [562242429 ] High CVE-2026-95351 Use after free in Views Reported by [Xinyang Ge ] on 2026-09-15 [$TBD] [562151598 ] Critical CVE-2026-95310 Use after free in AdFilter Reported by [Xinyang Ge ] on 2026-09-15 [$TBD] [560439699 ] Critical CVE-2026-95356 Use after free in WindowDialog Reported by [Xinyang Ge ] on 2026-09-12 [$TBD] [560536735 ] High CVE-2026-95306 Type confusion in V8 on 2026-09-12 [$TBD] [560536731 ] High CVE-2026-95304 Out of bounds write in V8 on 2026-09-12 [$TBD] [560406548 ] High CVE-2026-95280 Race condition in V8 on 2026-09-11 [$1000.0] [559815527 ] High CVE-2026-95343 Use after free in WebAudio Reported by [HoneyBee] on 2026-09-10 [$TBD] [559682346 ] Medium CVE-2026-95333 Use after free in Metrics on 2026-09-10 [$TBD] [558764482 ] High CVE-2026-95365 Type confusion in IndexedDB Reported by [~~Anaconda~~ HoneyBee] on 2026-09-08 [$500.0] [557523002 ] High CVE-2026-95286 Type confusion in Bindings on 2026-09-05 [$TBD] [556576976 ] High CVE-2026-95318 Buffer overflow in Video on 2026-09-03 [$1000.0] [556535630 ] High CVE-2026-95338 Use after free in PDFium on 2026-09-03 [$TBD] [555299641 ] High CVE-2026-95335 Use after free in HID Reported by [WinD39 - Huynh Dinh Vu] on 2026-08-31 [$TBD] [554558320 ] High CVE-2026-95348 Use after free in Bluetooth on 2026-08-29 [$TBD] [553921181 ] Low CVE-2026-95305 UI misrepresentation in Chromoting on 2026-08-28 [$TBD] [553271219 ] Low CVE-2026-95364 Improper input validation in Passwords on 2026-08-26 [$TBD] [553268567 ] Low CVE-2026-95340 Incorrect authorization in PictureInPicture on 2026-08-26 [$TBD] [553136141 ] High CVE-2026-95277 Use after free in Views on 2026-08-26 [$TBD] [553130481 ] High CVE-2026-95373 Use after free in DevTools on 2026-08-26 [$TBD] [553129513 ] High CVE-2026-95282 Use after free in Platform on 2026-08-26 [$TBD] [553123003 ] Medium CVE-2026-95311 Free of non-heap memory in Fonts on 2026-08-26 [$TBD] [553116160 ] High CVE-2026-95274 Improper output encoding in DevTools on 2026-08-26 [$TBD] [552665794 ] Critical CVE-2026-95313 Use after free in Fullscreen Reported by [WinD39 - Huynh Dinh Vu] on 2026-08-26 [$TBD] [552023752 ] Low CVE-2026-95316 Unchecked return value in Performance on 2026-08-24 [$TBD] [550953039 ] High CVE-2026-95293 Uninitialized resource in GPU on 2026-08-22 [$TBD] [549911100 ] Medium CVE-2026-95289 Incorrect authorization in Scroll on 2026-08-21 [$TBD] [548611433 ] Medium CVE-2026-95344 Race condition in DevTools on 2026-08-18 [$2500.0] [548585299 ] Critical CVE-2026-95339 Use after free in ServiceWorker on 2026-08-18 [$TBD] [547832510 ] Medium CVE-2026-95312 Information leak in Passwords Reported by [[goes here]] on 2026-08-17 [$TBD] [547027738 ] Low CVE-2026-95342 Missing authorization in V8 Reported by [Hongwei Li, Zhun Wang, Ziyue Pan, Junmin Zhu, Saastha Vasan, and Wenbo Guo] on 2026-08-16 [$TBD] [545449081 ] Medium CVE-2026-95300 Missing authorization in DevTools on 2026-08-12 [$TBD] [543464436 ] Medium CVE-2026-95374 Incorrect authorization in Network Reported by [NH DEV] on 2026-08-06 [$TBD] [542926849 ] Medium CVE-2026-95275 Incorrect reference resolution in MediaStream on 2026-08-05 [$5000.0] [540265100 ] High CVE-2026-95301 Missing authorization in Extensions on 2026-07-29 [$TBD] [537857253 ] High CVE-2026-95324 Uninitialized resource in GPU on 2026-07-22 [$TBD] [536648933 ] Medium CVE-2026-95325 Use after free in ANGLE on 2026-07-19 [$TBD] [536161355 ] Medium CVE-2026-95290 Missing authorization in NFC on 2026-07-17 [$TBD] [534997484 ] High CVE-2026-95372 Use after free in Chromecast on 2026-07-14 [$TBD] [534579660 ] Low CVE-2026-95380 Type confusion in V8 on 2026-07-13 [$TBD] [533095855 ] Low CVE-2026-95361 Confused deputy in DevTools on 2026-07-09 [$TBD] [533041383 ] Low CVE-2026-95326 Incomplete cleanup in Bluetooth on 2026-07-09 [$TBD] [532962621 ] Medium CVE-2026-95336 Information leak in Transactions Platform on 2026-07-09 [$TBD] [524582798 ] Medium CVE-2026-95354 Use after free in Verifier on 2026-06-16 [$TBD] [523719002 ] Medium CVE-2026-95341 Improper input validation in Desktop on 2026-06-13 [$TBD] [522413520 ] Low CVE-2026-95368 Incorrect authorization in DevTools on 2026-06-10 [$TBD] [522344883 ] Medium CVE-2026-95363 UI misrepresentation in FileSystem on 2026-06-10 [$TBD] [522061704 ] Medium CVE-2026-95353 Use after free in Bindings on 2026-06-09 [$TBD] [520516206 ] High CVE-2026-95298 Use after free in Browser on 2026-06-05 [$TBD] [517802696 ] Medium CVE-2026-95314 Incorrect authorization in HID on 2026-05-29 [$TBD] [517730821 ] Medium CVE-2026-95276 Improper input validation in Themes on 2026-05-28 [$TBD] [517661385 ] High CVE-2026-95315 Use after free in Aura on 2026-05-28 [$TBD] [517584808 ] Medium CVE-2026-95360 Race condition in Editing on 2026-05-28 [$TBD] [517442714 ] Medium CVE-2026-95303 Incomplete cleanup in SmartCard on 2026-05-28 [$TBD] [517417437 ] Medium CVE-2026-95370 Inappropriate implementation in NFC on 2026-05-28 [$TBD] [517163294 ] Medium CVE-2026-95330 Improper state validation in Downloads on 2026-05-27 [$TBD] [516404074 ] Medium CVE-2026-95345 Use after free in Actor on 2026-05-25 [$TBD] [514524620 ] Low CVE-2026-95367 Information leak in DataTransfer on 2026-05-18 [$TBD] [514487499 ] Medium CVE-2026-95317 Incorrect authorization in MediaCapture on 2026-05-18 [$TBD] [514072284 ] Medium CVE-2026-95320 Missing authorization in Navigation on 2026-05-17 [$TBD] [514059630 ] Medium CVE-2026-95346 UI misrepresentation in Chromoting on 2026-05-17 [$TBD] [513992281 ] Medium CVE-2026-95294 UI misrepresentation in Browser on 2026-05-17 [$TBD] [513791872 ] Low CVE-2026-95352 Incorrect authorization in DevTools on 2026-05-16 [$TBD] [513781838 ] Low CVE-2026-95292 Incorrect authorization in Safebrowsing on 2026-05-16 [$TBD] [513714849 ] Low CVE-2026-95308 Integer overflow in Metrics on 2026-05-15 [$TBD] [513403696 ] Low CVE-2026-95334 Incorrect reference resolution in WebProtect on 2026-05-14 [$TBD] [513134076 ] Medium CVE-2026-95376 Externally controlled reference in DevTools on 2026-05-14 [$TBD] [513049042 ] Medium CVE-2026-95369 Inappropriate implementation in XML on 2026-05-13 [$TBD] [511791538 ] Medium CVE-2026-95362 Cross-site request forgery in DevTools on 2026-05-10 [$TBD] [502179319 ] Medium CVE-2026-95375 Incorrect authorization in BrowserTag on 2026-04-13 [$TBD] [502077689 ] Low CVE-2026-95327 Information leak in Networking on 2026-04-13 [$TBD] [501648493 ] Medium CVE-2026-95297 Missing authorization in Contextual Tasks on 2026-04-11 [$TBD] [497603247 ] Medium CVE-2026-95381 Improper input validation in Printing on 2026-03-29 [$TBD] [497344014 ] Low CVE-2026-95278 Missing authorization in WakeLock on 2026-03-28 [$TBD] [497212105 ] Medium CVE-2026-95382 Improper input validation in Auth on 2026-03-28 [$TBD] [497204165 ] Medium CVE-2026-95366 Use of released resource in Core on 2026-03-28 [$TBD] [495529018 ] Medium CVE-2026-95287 Missing authorization in Navigation on 2026-03-23 [$500.0] [423956129 ] Low CVE-2026-95307 UI misrepresentation in ExtensionsMenu on 2025-06-10 [$TBD] [565328105 ] High CVE-2026-102321 Type confusion in V8 on 2026-09-23 [$TBD] [563716534 ] High CVE-2026-102302 Buffer overflow in V8 on 2026-09-19 [$5000.0] [563297615 ] High CVE-2026-102329 Cross-site scripting in WebUI on 2026-09-18 [$TBD] [562279351 ] High CVE-2026-102318 Out of bounds read in WebGL on 2026-09-15 [$1500.0] [562174487 ] High CVE-2026-102324 Use after free in PictureInPicture on 2026-09-15 [$TBD] [562042411 ] High CVE-2026-102319 Uninitialized resource in GPU on 2026-09-15 [$TBD] [562004351 ] High CVE-2026-102301 Out of bounds write in GPU on 2026-09-15 [$TBD] [561997480 ] High CVE-2026-102308 Use after free in Views on 2026-09-15 [$TBD] [561994362 ] High CVE-2026-102325 Uninitialized resource in Skia on 2026-09-15 [$TBD] [560536732 ] High CVE-2026-102328 Type confusion in V8 on 2026-09-12 [$TBD] [560251736 ] High CVE-2026-102304 Use after free in Passwords Reported by [Xinyang Ge ] on 2026-09-11 [$TBD] [560238698 ] High CVE-2026-102316 Use after free in Views Reported by [Xinyang Ge ] on 2026-09-11 [$TBD] [560233248 ] High CVE-2026-102326 Type confusion in V8 on 2026-09-11 [$2000.0] [560062638 ] High CVE-2026-102300 Uninitialized resource in WebGPU on 2026-09-11 [$TBD] [559266114 ] High CVE-2026-102323 Type confusion in V8 on 2026-09-09 [$TBD] [556926296 ] High CVE-2026-102306 Use after free in Bluetooth on 2026-09-03 [$500.0] [556908674 ] High CVE-2026-102299 Type confusion in V8 on 2026-09-03 [$TBD] [554038924 ] Medium CVE-2026-102320 Missing authorization in CORS on 2026-08-28 [$TBD] [514059780 ] Low CVE-2026-102314 UI misrepresentation in TabStrip on 2026-05-17 [$TBD] [498793976 ] Low CVE-2026-102330 Incorrect authorization in SiteIsolation on 2026-04-01 [$1000.0] [477726837 ] Low CVE-2026-102310 Missing authorization in Payments on 2026-01-21 [$TBD] [567088927 ] High CVE-2026-103631 Buffer overflow in WebRTC on 2026-09-28 [$TBD] [565742180 ] High CVE-2026-103623 Use after free in MediaStream on 2026-09-24 [$TBD] [565742179 ] High CVE-2026-103622 Use after free in SVG on 2026-09-24 [$TBD] [559893859 ] High CVE-2026-103625 Type confusion in V8 on 2026-09-10 [$TBD] [557323166 ] High CVE-2026-103630 Use after free in FedCM on 2026-09-04 [$TBD] [556268833 ] High CVE-2026-103621 Integer overflow in Compositing on 2026-09-02 [$TBD] [553147154 ] Medium CVE-2026-103627 Information leak in SVG on 2026-08-26 [$TBD] [549995090 ] Critical CVE-2026-103628 Out of bounds write in WebGL on 2026-08-20
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.