Google Chrome < 154.0.8037.92 Multiple Vulnerabilities

critical Nessus Plugin ID 351209

Synopsis

A web browser installed on the remote macOS host is affected by multiple vulnerabilities.

Description

The version of Google Chrome installed on the remote macOS host is prior to 154.0.8037.92. It is, therefore, affected by multiple vulnerabilities as referenced in the 2026_09_stable-channel-update-for-desktop_01807488085 advisory.

- Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) (CVE-2026-102331)

- Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) (CVE-2026-102324)

- Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) (CVE-2026-102299, CVE-2026-102321, CVE-2026-102323, CVE-2026-102326, CVE-2026-102328)

- Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) (CVE-2026-102300)

- Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) (CVE-2026-102301)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Google Chrome version 154.0.8037.92 or later.

See Also

https://crbug.com/477726837

https://crbug.com/496212975

https://crbug.com/498793976

https://crbug.com/514059780

https://crbug.com/517312707

https://crbug.com/533021953

https://crbug.com/551668264

https://crbug.com/551673541

https://crbug.com/554038924

https://crbug.com/556789073

https://crbug.com/556908674

https://crbug.com/556926296

https://crbug.com/556959073

https://crbug.com/559266114

https://crbug.com/559727039

https://crbug.com/559737160

https://crbug.com/560062638

https://crbug.com/560233248

https://crbug.com/560238698

https://crbug.com/560251736

https://crbug.com/560536732

https://crbug.com/560867085

https://crbug.com/561994362

https://crbug.com/561997480

https://crbug.com/562004351

https://crbug.com/562042411

https://crbug.com/562174487

https://crbug.com/562279351

https://crbug.com/563297615

https://crbug.com/563351482

https://crbug.com/563716534

https://crbug.com/565328105

http://www.nessus.org/u?e41e8473

Plugin Details

Severity: Critical

ID: 351209

File Name: macosx_google_chrome_154_0_8037_92.nasl

Version: 1.1

Type: Local

Agent: macosx

Published: 9/29/2026

Updated: 9/29/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.19

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-102324

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-102331

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: installed_sw/Google Chrome

Exploit Ease: No known exploits are available

Patch Publication Date: 9/29/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-102299, CVE-2026-102300, CVE-2026-102301, CVE-2026-102302, CVE-2026-102303, CVE-2026-102304, CVE-2026-102305, CVE-2026-102306, CVE-2026-102307, CVE-2026-102308, CVE-2026-102309, CVE-2026-102310, CVE-2026-102311, CVE-2026-102312, CVE-2026-102313, CVE-2026-102314, CVE-2026-102315, CVE-2026-102316, CVE-2026-102317, CVE-2026-102318, CVE-2026-102319, CVE-2026-102320, CVE-2026-102321, CVE-2026-102323, CVE-2026-102324, CVE-2026-102325, CVE-2026-102326, CVE-2026-102327, CVE-2026-102328, CVE-2026-102329, CVE-2026-102330, CVE-2026-102331