Chrome Just Patched 108 Security Flaws. Most People Have Not Installed It.

by Sep 28, 2026Business, security, software, Technology0 comments

Chrome 154 security update patching 108 vulnerabilities

The short version

  • Chrome 154 fixes 108 security flaws, 11 of them rated critical.
  • None are known to be exploited yet, so this is a patch-promptly job rather than an emergency.
  • Chrome downloads the update on its own but only applies it when the browser fully restarts.
  • Edge, Brave and Opera run the same engine and need the same check.

Google released Chrome 154 on September 22 with 108 security fixes, 11 of them rated critical. Several of the critical ones sit in the graphics layer that renders whatever page you happen to be on, which means the delivery mechanism is a web page rather than a download or an attachment. Nobody has to be tricked into opening anything.

None of the 108 are being exploited in the wild yet, so this is not a drop-everything situation. It is the more ordinary kind of important. Google found 76 of them internally and outside researchers reported the rest, and the gap between a public patch and working exploit code keeps shrinking, because the fix itself shows attackers exactly where to look.

The part that actually matters

Chrome updates itself quietly in the background, which is why most people assume they are covered. The update does not take effect until Chrome fully restarts, and plenty of people never close it. Tabs stay open for weeks, laptops get shut without quitting anything, and the patched version sits on disk doing nothing.

So the honest status of most machines in most offices this morning is: update downloaded, not applied. Checking takes about ten seconds. Open the three-dot menu, then Help, then About Google Chrome. If it offers a Relaunch button, you were not patched.

Versions you should see

  • Windows and Mac: 154.0.8037.57 or .58
  • Linux: 154.0.8037.57
  • Android: 155.0.8059.16

Chrome is not the only one

Edge, Brave, Opera and Arc are all built on the same Chromium engine, so the same flaws apply to them. Each vendor ships its own update on its own schedule. If your staff use a mix of browsers, every one of them needs checking, and Edge is the one people forget because it arrived with Windows rather than being installed on purpose.

If your machines are managed

Browser updates can be enforced rather than requested. Chrome and Edge both support policies that install updates centrally and force a relaunch after a set period, which turns this from an email asking people to do something into something that has already happened. Without that, your patch compliance depends on how tidy your staff are about closing applications, and that is not a security control.

A browser is the most exposed application on a business laptop. It runs untrusted code from dozens of sources every hour, by design, and that is the job. Something sitting in that position while three weeks behind on eleven critical fixes is worth ten seconds and a relaunch.

Do you know what your fleet is actually running?

PTSI manages browser and operating system patching for New York businesses, including forced relaunch policies, so updates land instead of waiting for someone to close their tabs.

Talk to PTSI

PTSI Editorial Team

Support Line: Phone: +1 646-535-HELP (4357) Email: helpdesk@progressny.com Support web: helpdesk.progressny.com