ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Plate 30

  1. Blog

Chrome 154.0.8037.97: the 1 October 2026 security update for site owners

Google’s 1 Oct 2026 stable desktop post moves Chrome to 154.0.8037.97/.98 on Windows and Mac, with 11 security fixes. The same day’s Android note names a different Linux build. No exploit steps, and no affiliate.

Aditya Challa·3 October 2026·6 min read

Summary
On this page
  1. Related links
  2. What the stable post says
  3. Do not mix up the Linux line
  4. The 11 fixes, as Chrome named them
  5. What that means on a product page
  6. What to do

Chrome 154.0.8037.97: the 1 October 2026 security update for site owners

Google posted a Stable channel desktop update on Thursday, October 1, 2026. The post does not print a timezone. ShopperCove did not install this build. The version numbers and the bug list below are copied from Chrome’s own release posts, fetched 3 Oct 2026. This is not a feature tour, and it is not the earlier ShopperCove note on Chrome DevTools AI assistance.

There is no affiliate link in this article.

Related links

  • https://www.shoppercove.com/blog/nextjs-16-3-8-security-release-2026
  • https://www.shoppercove.com/blog/tanstack-start-xss-cve-2026-102989-patch
  • https://www.shoppercove.com/blog/chrome-devtools-ai-assistance-gemini-guide-2026

What the stable post says

The Stable Channel Update for Desktop says the Stable channel has been updated to:

  • 154.0.8037.97/.98 for Windows and Mac
  • 154.0.8037.97 for Linux

Google says that build will roll out over the coming days or weeks. If About Chrome still shows an older 154 or a 153 build, that can be the rollout, not a sign the post was wrong.

The same post says this update includes 11 security fixes. It also says access to bug details and links may stay restricted until a majority of users are updated, and may stay restricted if the bug is in a third-party library other projects still depend on. This article does not add exploit steps, payloads, or crash inputs. Those details are not on the public release note.

Do not mix up the Linux line

The desktop stable post names Linux 154.0.8037.97. The same day’s Chrome for Android note, also Thursday, October 1, 2026, says Android releases contain the same security fixes as the corresponding desktop releases, and then it writes: Windows and Mac 154.0.8037.97/.98, Linux 153.0.8010.97, unless otherwise noted.

Those two Google posts do not name the same Linux build. Windows and Mac 154.0.8037.97/.98 match in both places. Android’s own build on that note is 154.0.8037.126, rolling out on Google Play over the next few days. Treat the Linux number as unsettled until you read the build Chrome actually installed. Do not “correct” a Linux machine to 153, or to 154, just to match one of the two sentences.

A later post on the October index is not a newer stable desktop security update. On Friday, October 2, 2026, Chrome’s Extended Stable channel moved to 152.0.7977.152 for Windows and Mac. That is a different channel. Dev channel posts the same day moved Dev to 157.0.8081.0 on desktop. Dev is not the stable fix. As of the October 2026 index fetched 3 Oct 2026, the newest stable desktop security note was still the October 1 post.

The 11 fixes, as Chrome named them

Severities below are Chromium’s labels on the release post (Critical, High, Medium). The post does not print CVSS scores, and this article does not add any. Reward fields on the post are N/A or TBD, not dollar amounts.

  • Critical CVE-2026-103628: out of bounds write in WebGL. Reported by Google on 2026-08-21.
  • High CVE-2026-103626: incorrect authorization in FileSystem. Reported by Google on 2026-08-26.
  • High CVE-2026-103621: integer overflow in Compositing. Reported by Google on 2026-09-02.
  • High CVE-2026-103630: use after free in FedCM. Reported by xinyang on 2026-09-04.
  • High CVE-2026-103625: type confusion in V8. Reported by Google on 2026-09-11.
  • High CVE-2026-103624: use after free in Contextual Tasks. Reported by xuanocto1221 on 2026-09-15.
  • High CVE-2026-103629: integer overflow in Skia. Reported by Google on 2026-09-15.
  • High CVE-2026-103622: use after free in SVG. Reported by xinyang on 2026-09-24.
  • High CVE-2026-103623: use after free in MediaStream. Reported by xinyang on 2026-09-24.
  • High CVE-2026-103631: buffer overflow in WebRTC. Reported by Xinyang Ge (Anthropic), assisted by Claude, on 2026-09-28. That reporter line is Chrome’s wording.
  • Medium CVE-2026-103627: information leak in SVG. Reported by Google on 2026-08-26.

What that means on a product page

You do not need a WebGL product viewer for this to matter. The critical item is in the browser’s WebGL code. A customer on an unpatched Chrome is the one who needs the update, including when they are shopping on your site. If your pages do use a 3D or WebGL viewer, that is an extra reason not to leave staff browsers behind, not a reason to ship a workaround from this post.

SVG is the other frontend-facing pair: a high-severity use after free (CVE-2026-103622) and a medium information leak (CVE-2026-103627). Inline SVG icons, logos, and illustrations are ordinary on product pages. The fix is still the browser update. Nothing in the release note says to stop using SVG.

FedCM is Chrome’s federated sign-in surface. If you offer “Sign in with Google” or a similar FedCM flow, the high-severity use after free is in that component. V8 is the JavaScript engine, so it sits under every storefront. Skia and compositing are rendering. MediaStream and WebRTC matter if you embed camera, mic, or calling. FileSystem is the browser file API. Contextual Tasks is a Chrome UI surface, not your app code.

None of these are Next.js, SvelteKit, or Remix patches. The Next.js 16.3.8 post linked above is a separate server release. Do not describe 16.3.8 as the fix for CVE-2026-94545. That earlier next/og issue was patched in 16.3.6, and it is not in this Chrome list.

What to do

  1. On desktop, open Chrome’s About page (chrome://settings/help) and let Stable finish updating, then restart. The target on Windows and Mac is 154.0.8037.97 or .98, or a later stable build if one has shipped since 1 Oct 2026. ShopperCove did not see a newer stable desktop post on the October index.
  2. On Linux, update Stable, then read the version Chrome reports. Do not force 153.0.8010.97 or 154.0.8037.97 just to reconcile the two Google sentences.
  3. On Android, the 1 Oct post is 154.0.8037.126 on Google Play, not the desktop build number.
  4. Leave Extended Stable and Dev alone unless you already use that channel on purpose. Extended Stable’s 2 Oct build is 152, not 154. Dev 157 is not the stable security update.
  5. This does not patch your framework, your CDN, or a customer’s other browsers. Firefox 157 is a different release and is not covered here.

The DevTools Gemini guide linked above is about Chrome’s AI panel. It is not this security update.

chromesecurity updatecvewebglv8fedcmbrowser securitypatch

Lab evidence

What I found running this

Primary pages fetched 3 Oct 2026 from Chrome’s stable channel post and Shopify’s Canvas newsroom and changelog. ShopperCove did not install the Chrome build and did not open a Shopify admin. Version numbers and launch limits are quoted from those pages, not measured here.

Notes when a lab post goes up

Occasional email for new hands-on reviews. No sequence and no sponsors.

Related links

  • Plate 66

    Next.js 16.3.8 security release: SSRF, cache, and OG routes (and the earlier next/og RCE)

    Next.js 16.3.8 (30 Sep 2026) covers image SSRF and cache bugs. CVE-2026-94545, the next/og RCE, was patched in 16.3.6 and is not a 16.3.8 fix.

    3 Oct 2026

  • Plate 35

    Shopify Canvas launched 1 Oct 2026: what Sidekick edits, and what it skips

    Canvas is Shopify’s 1 Oct 2026 design surface for Sidekick. The changelog lists what you can edit and what is missing at launch, including third-party themes and app blocks. No separate price was on those pages. No affiliate.

    3 Oct 2026

  • Plate 12

    InstaDoodle: prompt-to-doodle videos, and where it differs from a character library

    InstaDoodle turns a text prompt into a browser doodle video, unlike a character library. 60-day guarantee was on the page. One hop.

    3 Oct 2026

On this page

  1. Related links
  2. What the stable post says
  3. Do not mix up the Linux line
  4. The 11 fixes, as Chrome named them
  5. What that means on a product page
  6. What to do
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove