Chrome Hit by Dozens of Critical Vulnerabilities
The Hong Kong Computer Emergency Response Team Coordination Centre has issued a security bulletin warning of multiple vulnerabilities in Google Chrome. The vulnerabilities, identified as CVE-2026-95274 through CVE-2026-95375 and CVE-2026-95380 through CVE-2026-95382, could allow a remote attacker to trigger denial of service conditions, security restriction bypasses, sensitive information disclosure, spoofing, cross-site scripting, data manipulation, and remote code execution on targeted systems. The affected versions of Google Chrome are prior to 154.0.8037.57 for Linux, Mac, and Windows.
The bulletin advises users to apply fixes issued by the vendor, which includes updating to version 154.0.8037.57 or later for each platform. The vulnerabilities were identified in September 2026.