Google Chrome Patches 12 Vulnerabilities, Fixing Browser Attack Risk
Key Takeaways Google has released a critical Stable channel update for Chrome, addressing 12 security vulnerabilities. Nine of these flaws are rated “High” severity, posing risks such as...
Key Takeaways
- Google has released a critical Stable channel update for Chrome, addressing 12 security vulnerabilities.
- Nine of these flaws are rated “High” severity, posing risks such as arbitrary code execution and memory corruption.
- The update brings Chrome to versions 150.0.7871.181/.182 for Windows/Mac and 150.0.7871.181 for Linux.
- Users and enterprise administrators are strongly advised to update immediately to mitigate potential exploitation risks.
Google has rolled out a significant security update for its Chrome browser, patching a dozen vulnerabilities, with nine classified as “High” severity. This essential update elevates Chrome to version 150.0.7871.181/.182 for Windows and Mac users, and 150.0.7871.181 for Linux, with phased deployment expected to reach all users in the coming days and weeks.
Many of the resolved issues could enable attackers to corrupt memory, execute arbitrary code, or bypass security mechanisms. This makes the update a critical priority for both individual users and organizational IT departments responsible for maintaining secure browser environments.
Chrome Update Addresses 12 Vulnerabilities
The update addresses flaws across various core Chrome components, including V8, ANGLE, Skia, GPU, UI, Extensions, and Chromecast. Below is a detailed breakdown of the patched vulnerabilities:
| CVE ID | Severity | Vulnerability Type | Component | Reported By | Date Reported |
|---|---|---|---|---|---|
| CVE-2026-16413 | High | Out of bounds write | ANGLE | 2026-05-28 | |
| CVE-2026-16414 | High | Insufficient validation of untrusted input | Chromecast | 2026-05-28 | |
| CVE-2026-16415 | High | Insufficient validation of untrusted input | Extensions | 2026-06-02 | |
| CVE-2026-16416 | High | Integer overflow | Chromecast | 2026-06-05 | |
| CVE-2026-16417 | High | Uninitialized use | Skia | 2026-06-08 | |
| CVE-2026-16418 | High | Stack buffer overflow | V8 | 2026-06-10 | |
| CVE-2026-16419 | High | Out of bounds read and write | ANGLE | 2026-06-13 | |
| CVE-2026-16420 | High | Type Confusion | WebAudio | XBOW (triaged by Brendan Dolan-Gavitt) | 2026-06-26 |
| CVE-2026-16421 | High | Inappropriate implementation | WebAudio | XBOW (triaged by Brendan Dolan-Gavitt) | 2026-06-26 |
| CVE-2026-16422 | High | Insufficient validation of untrusted input | Certificate | 2026-07-10 | |
| CVE-2026-16423 | High | Use after free | UI | 2026-07-14 | |
| CVE-2026-16424 | High | Use after free | GPU | 2026-07-14 |
Among the patched vulnerabilities, two—CVE-2026-16420 and CVE-2026-16421—were identified by XBOW, an autonomous AI-driven security research platform, and further analyzed by researcher Brendan Dolan-Gavitt. Each of these discoveries merited a $500 bounty reward.
The remaining ten vulnerabilities were found through internal efforts by Google’s dedicated security teams, with discovery dates ranging from late May to mid-July 2026.
Understanding the Risk
Vulnerabilities such as type confusion, use-after-free, and buffer overflows are particularly concerning due to their direct impact on Chrome’s memory management.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.