Vivaldi Desktop 8.2 minor update 4: install update 5 instead
Vivaldi shipped a fifth minor update for Desktop 8.2 on September 18, 2026, just one day after minor update 4 landed. If your Vivaldi browser stopped at update 4, you're already behind on the newest Chromium security patch, according to Vivaldi's release notes.
That gap matters because Vivaldi's update posts don't always make clear which build supersedes which. Update 4, released on September 17, patched a script-injection security issue in Vivaldi Mail and fixed a broken "Accept" button in Calendar. Update 5 builds directly on top of that work with a newer Chromium Extended Stable Release build, 152.0.7977.137 ESR, according to Vivaldi's update 5 release notes. Vivaldi Desktop 8.2 users should check their build number now: the target is 152.0.7977.137 ESR or later, not the .134 build that shipped with update 4 alone.
What Vivaldi 8.2 update 4 fixed
Update 4's headline fix addresses a script-injection security issue in Vivaldi Mail, tracked internally as VB-131004. Vivaldi's changelog lists the issue and marks it as "a security fix from us," distinct from the Chromium-side patches bundled into the same release, according to Vivaldi.
The same update also bumped Chromium itself to 152.0.7977.134 ESR, folding in security work from Chromium 153.0.8010.47.
Two everyday annoyances got cleaned up in the same release. Clicking "Accept" on a Calendar invitation had been doing nothing, a bug tracked as VB-131622. Audio feeds had also lost their sound entirely, tracked as VB-131543. Both fixes came bundled into update 4, according to Vivaldi.
If you rely on Vivaldi's built-in Calendar to manage meeting invites, that Accept bug wasn't cosmetic. It was a workflow failure: invitations arrived, but responding to them silently failed. Anyone who updated to build .134 should confirm Accept now actually registers, since a fix listed in a changelog isn't the same as confirming it behaves correctly on your machine.
What the Vivaldi Desktop 8.2 security update does not disclose
The release note for update 4 lists the Mail script-injection issue and marks it as a security fix, but it does not state the bug's severity, the conditions needed to exploit it, or whether it was found internally or reported by an outside researcher, according to Vivaldi.
That's a notable gap compared to how Vivaldi described an earlier fix in the same 8.2 cycle. The September 4 patch, issued 13 days before update 4, named a specific vulnerability: CVE-2026-85046, a type-confusion bug in V8 that Vivaldi said had a known exploit already circulating in the wild, according to Vivaldi. That release note included a CVE number, a technical description, and an explicit statement about active exploitation.
Update 4's Mail fix includes none of that context in Vivaldi's own release note. Treat it as a confirmed fix with limited public documentation, not evidence that anyone was actively exploiting the bug before the patch shipped. Vivaldi's notes give no basis for rating the urgency of update 4 beyond the standard advice: install it.
Why the Vivaldi Chromium 152 ESR update in update 5 matters
Update 5 arrived a single day after update 4, and its changelog frames its fixes as changes made "since the fourth 8.2 minor update," confirming it's cumulative on top of update 4 rather than a separate patch branch, according to Vivaldi's update 5 release notes.
The core change is a Chromium bump to 152.0.7977.137 Extended Stable Release, incorporating security fixes from Chromium 153.0.8010.52 and .53, a step up from the 153.0.8010.47 fixes that shipped with update 4's .134 build a day earlier, according to Vivaldi. Anyone still on .134 has update 4's Mail and Calendar fixes but not this additional Chromium security work.
Update 5 also patches a "small tabs" display issue, tracked as VB-131314, that update 4 left untouched, according to Vivaldi. It isn't a security fix, but it confirms update 4 and update 5 shipped different code, not two labels for the same build.
Calendar and feed fixes across the 8.2 cycle
The Calendar problems fixed in update 4 weren't isolated. A week before update 4 shipped, Vivaldi issued a separate fix for a Calendar display-sanitization issue, tracked as VB-130990, in minor update 2 on September 11, according to Vivaldi. That update also touched a calculator rounding bug and vertical tab spacing, alongside a Chromium bump to 152.0.7977.124 ESR with security fixes from Chromium 153.0.8010.36 and .37.
Taken together, Vivaldi has issued multiple Calendar-related fixes during the 8.2 cycle: a display-sanitization patch in update 2, then the broken Accept button in update 4. Calendar users should test invitation acceptance after each update rather than assuming a fix from one release still holds in the next.
Tracking the full 8.2 patch sequence
Vivaldi's 8.2 release launched on September 3, 2026, introducing a local calculator built into the address bar and easier Progressive Web App installation, according to Vivaldi. Since then, Vivaldi has published dated maintenance posts on September 4, 11, 17, and 18. Each post includes Chromium security work alongside other bug fixes or polish, based on the entries reviewed here.
Update 4's own changelog states its changes were made "since the third 8.2 minor update," according to Vivaldi, confirming a third minor update existed even though its separate release post isn't part of this reporting. The numbering jumps from update 2 to update 4 in the sources reviewed here, not because Vivaldi skipped a release, but because that specific post wasn't included in this research.
The three fully documented releases line up like this:
| Release | Date | Chromium build | Key fixes |
|---|---|---|---|
| Update 2 | Sept 11, 2026 | 152.0.7977.124 ESR (153.0.8010.36/37) | Calendar display sanitization (VB-130990), calculator rounding (VB-131340), vertical tab spacing (VB-131200) |
| Update 4 | Sept 17, 2026 | 152.0.7977.134 ESR (153.0.8010.47) | Mail script injection (VB-131004), Calendar Accept button (VB-131622), audio feed sound (VB-131543) |
| Update 5 | Sept 18, 2026 | 152.0.7977.137 ESR (153.0.8010.52/53) | Small tabs display issue (VB-131314) |
Sourced from Vivaldi's update 2, update 4, and update 5 release notes.
What to check before you assume you're current
The release notes cited here don't specify the exact menu path for checking your installed build or how Vivaldi stages its update rollout across users. Check the installed version in Vivaldi's built-in version/update screen instead of guessing based on when you last saw an update prompt.
If that screen reports a build earlier than 152.0.7977.137 ESR, install the latest available Desktop 8.2 update now; update 4 alone leaves the newest Chromium security work uninstalled. If it already reports .137 or later, the build matches what Vivaldi's own release notes describe as current, and no further action from this reporting is needed.



Comments
Be the first, drop a comment!