Google released a new stable Chrome 154 update on September 29. The published versions are 154.0.8037.92 for Linux and .92/.93 for Windows and macOS. A September 30 GovCERT alert says multiple vulnerabilities could expose users to several kinds of impact, including remote code execution.
Affected versions
CERT-FR’s thresholds are versions earlier than 154.0.8037.92 on Linux and Windows, and earlier than 154.0.8037.93 on macOS. The Chrome team’s stable update addresses these versions and is rolling out gradually.
Google says this release includes 32 fixes: one critical vulnerability, 25 high, one medium and five low. The published critical flaw, CVE-2026-102331, is a buffer overflow in ANGLE. Google says some details remain restricted during rollout; these severity levels do not describe one shared exploitation scenario.
Several possible impacts
The alert lists potential consequences including remote code execution, denial of service, privilege escalation, information disclosure, security-restriction bypass, spoofing and tampering. These categories cover multiple vulnerabilities and do not mean they can all be exploited in the same way.
GovCERT describes a scenario in which an attacker entices a user to open a page containing specially crafted content in a vulnerable browser. The advisories reviewed do not report active exploitation of this update batch; that lack of reporting does not prove none exists.
Check and install the update
On each device, open “About Google Chrome” from the browser menu. The page checks for an update and displays the installed version. After the new version downloads, relaunch Chrome to finish applying it.
Organizations can verify deployment through their endpoint-management tools and check devices that stay on continuously. Embedded browsers may follow a separate update schedule, so check with the application vendor where relevant.
Reduce exposure during rollout
Until every device is updated, limit use of devices that cannot be patched and avoid opening unexpected links. This precaution does not replace the update: malicious content does not have to be downloaded as a file to be processed by a browser.
After the fleet is updated, keep a version inventory and identify offline devices. That distinguishes a completed rollout from a notice that was merely sent to users.
How Soclyde fits
This update concerns the browser; Soclyde does not distribute it or protect Chrome from its vulnerabilities. By itself, it does not call for a password change. For a separate account incident, see our SMB password policy guide and guide to sharing passwords securely with a team.
Key points
Install at least Chrome 154.0.8037.92 on Linux and Windows or 154.0.8037.93 on macOS, then relaunch the browser. Check managed devices instead of relying only on an update notification. To limit the impact of a separate incident affecting an account, read our guide to creating strong, unique passwords.



