ChromeOS 16805.33.0 fixes 106 Chrome bugs, five of them Critical
EditorialBy TrustList Editorial
The update also carries two High third-party fixes, one in the mali_kbase GPU driver and one that weakened the crosvm sandbox. Google's post does not say any of the bugs is being exploited.
About ChromeOS 16805.33.0 fixes 106 Chrome bugs, five of them Critical
ChromeOS 16805.33.0 fixes 106 Chrome bugs, five of them Critical
9 October 2026: Google has pushed ChromeOS and ChromeOS Flex Stable to OS version 16805.33.0, built on Chrome 154.0.8037.151, and the release notes list 106 security fixes in the browser. Counting the list, 5 are rated Critical, 44 High, 37 Medium and 20 Low. Google does not say that any of them is being exploited.
Not yet independently verified. The counts are ours, taken from the list in Google's post. Google lists most bug bounty rewards as still to be decided and does not give an exploitation status for any fix. We will update this when it can be confirmed, and remove this note.
The two Critical bugs at the top of the list are use-after-free flaws, one in AdFilter (CVE-2026-95310) and one in WindowDialog (CVE-2026-95356). The High group is dominated by memory-safety faults in components every Chromebook runs: three in the V8 JavaScript engine (a type confusion, an out-of-bounds write and a race condition), plus use-after-free bugs in WebAudio, PDFium, Bluetooth and HID.
Beyond the browser, the post names two High fixes from third parties. One is a use-after-free write in the mali_kbase GPU driver, in delete_hoarded_chunks, which lets code in the GPU process corrupt kernel memory. The other is a StartArcVm field, wayland_server, that was not validated and could weaken the crosvm sandbox, the virtual machine boundary used for Android apps on Chromebooks. The post gives Android security fixes a separate link and lists no ChromeOS Vulnerability Rewards Program entries for this release.
The update is for most ChromeOS devices. Google's post gives no device list and does not mention the long-term support or Extended Stable channels, so a fleet pinned to either should check its own channel's notes rather than assume this build applies.
For administrators the questions are practical ones. Check that the auto-update policy lets devices take Stable releases, that no pinned target version is holding managed Chromebooks and Flex machines below 16805.33.0, and that devices have been restarted, since an update only applies after a reboot. Schools with carts of devices that rarely restart are the likeliest to lag.
Our mobile device management software category lists eight products for managing fleets like these.
Google dated the post 9 October 2026 and signed it from the ChromeOS team.
Company profile on TrustList: Google
Related on TrustList:
- Google stops paying bounties for flaws in Go, Angular and other OSS
- Apple patches an exploited CoreGraphics flaw: push iOS 26.7.1, iPadOS 26.7.1 and the macOS updates to managed devices
Sources
Categories & features
- Cybersecurity
- Vulnerability Assessment
- Endpoint Management
- For Schools
- United States
- California
- Mountain View, Ca
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.