Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft August 2026 Patch Tuesday fixes 394 flaws, including 3 zero-days
August 11, 2026
Critical Zoom Zero-Click Flaws Let Attackers Hijack User Devices
August 11, 2026
DEF CON Attendees Broadcast Fake Wi-Fi Network on Flight
August 11, 2026
Home/CyberSecurity News/Critical Chrome Vulnerabilities Allow Arbitrary Code Execution
CyberSecurity News

Critical Chrome Vulnerabilities Allow Arbitrary Code Execution

Key Takeaways Google has rolled out an urgent security update for its Chrome browser, addressing 33 vulnerabilities. Seven of these flaws are rated critical, primarily “use-after-free”...

Sarah simpson
Sarah simpson
June 17, 2026 3 Min Read
47 0

Key Takeaways

  • Google has rolled out an urgent security update for its Chrome browser, addressing 33 vulnerabilities.
  • Seven of these flaws are rated critical, primarily “use-after-free” memory corruption bugs, enabling arbitrary code execution.
  • Affected Chrome versions include those prior to 149.0.7827.155/.156 for Windows/macOS and 149.0.7827.155 for Linux.
  • Immediate updating is strongly recommended to mitigate the risk of remote code execution through malicious webpages.

Google has issued a critical security patch for its Chrome browser, urging users to update promptly. This comprehensive update addresses numerous high-severity vulnerabilities, including several critical flaws that could allow attackers to execute arbitrary code on compromised systems.

Table Of Content

  • Key Takeaways
  • Critical Vulnerabilities Enabling Code Execution
  • Other Notable Vulnerabilities
  • What You Should Do

The stable channel of Chrome has been updated to version 149.0.7827.155/.156 for Windows and macOS, and 149.0.7827.155 for Linux. Google’s official release notes detail 33 security fixes, many of which carry a critical rating due to their potential for remote code execution (RCE).

In line with standard security practices, Google is withholding detailed technical specifics for some vulnerabilities. This measure aims to prevent threat actors from developing exploits before a substantial portion of the user base has applied the necessary updates.

Critical Vulnerabilities Enabling Code Execution

The most severe issues patched are seven critical vulnerabilities, predominantly categorized as “use-after-free” memory corruption bugs. These types of flaws are particularly dangerous as they enable attackers to manipulate memory, potentially leading to arbitrary code execution within the browser’s operational context.

The critical vulnerabilities addressed include:

  • CVE-2026-12437: A use-after-free vulnerability identified in WebShare.
  • CVE-2026-12438: An inappropriate implementation flaw affecting WebView.
  • CVE-2026-12439 & CVE-2026-12440: Two distinct use-after-free vulnerabilities found within Digital Credentials.
  • CVE-2026-12441: A use-after-free bug impacting File Input.
  • CVE-2026-12442: A use-after-free vulnerability present in the Passwords component.
  • CVE-2026-12443: A use-after-free flaw affecting Web Authentication.

Use-after-free vulnerabilities occur when a program attempts to access memory that has already been deallocated. This can lead to memory corruption, allowing an attacker to inject malicious code and control the program’s execution flow. In practical terms, an attacker could exploit these vulnerabilities simply by luring a victim to a specially crafted malicious webpage, requiring no further user interaction.

Beyond the critical issues, Google also rectified numerous high-severity vulnerabilities across various components, including WebRTC, Extensions, Safe Browsing, GPU, and File System Access.

Other Notable Vulnerabilities

The update also includes fixes for several high-severity issues that could be leveraged for further attacks or data exfiltration:

  • Heap buffer overflows in WebRTC (CVE-2026-12447, CVE-2026-12466).
  • Out-of-bounds reads affecting Chromoting (CVE-2026-12444) and WebRTC (CVE-2026-12461).
  • Multiple use-after-free flaws in Extensions (CVE-2026-12445, CVE-2026-12467), Media (CVE-2026-12462), Downloads (CVE-2026-12452), and the Browser itself (CVE-2026-12464).
  • Insufficient validation and policy enforcement issues across input handling (CVE-2026-12453, CVE-2026-12456, CVE-2026-12457, CVE-2026-12465) and extensions (CVE-2026-12460).

These vulnerabilities, while not all critical, could still lead to severe consequences such as data leaks, sandbox escapes, or could be chained together to achieve more significant compromises. The comprehensive nature of this patch highlights Google’s ongoing commitment to browser security, often through the proactive identification of memory safety issues using internal security tools like AddressSanitizer, MemorySanitizer, libFuzzer, and Control Flow Integrity mechanisms.

What You Should Do

  • Update Chrome Immediately: Navigate to Settings > About Chrome within your browser to initiate the update process.
  • Restart Your Browser: Ensure the patches are fully applied by restarting Chrome after the update is complete.
  • Monitor Enterprise Environments: IT administrators should verify that all managed Chrome instances are updated to the latest secure versions.
  • Implement Defense-in-Depth: Supplement browser updates with robust endpoint protection and consider browser isolation solutions to enhance overall security posture.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical LiteLLM Flaw CVE-2024-4236 Lets Attackers Bypass Authentication

Next Post

AIRecon: AI Penetration Testing Tool Integrates Kali Linux Sandbox

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk
August 11, 2026
Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
August 11, 2026
Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us