Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Top CISOs Boost Risk Visibility to Prevent Critical Incidents
May 27, 2026
Hackers Push Malicious Software Via AI Chatbot Recommendations
May 27, 2026
Motorola Preinstalled App Hijacks Amazon for Affiliate Codes
May 27, 2026
Home/CyberSecurity News/Critical Chrome Flaws Allow Remote Code Execution Attacks
CyberSecurity News

Critical Chrome Flaws Allow Remote Code Execution Attacks

Google has issued an urgent security update for its Chrome browser. The patch addresses 16 vulnerabilities, including two rated Critical that could allow attackers to execute arbitrary code remotely...

Emy Elsamnoudy
Emy Elsamnoudy
May 21, 2026 2 Min Read
18 0

Google has issued an urgent security update for its Chrome browser. The patch addresses 16 vulnerabilities, including two rated Critical that could allow attackers to execute arbitrary code remotely on affected systems.

Table Of Content

  • Critical Chrome Vulnerabilities Patched
  • High-Severity Vulnerabilities Patched
  • Other Medium-Severity Fixes
  • Mitigations

The Stable channel has been updated to 148.0.7778.178/179 for Windows and Mac, and 148.0.7778.178 for Linux, with the rollout expected to complete over the coming days.

Critical Chrome Vulnerabilities Patched

The two most severe flaws both carry a Critical severity rating and were reported internally by Google on April 20, 2026:

  • CVE-2026-9111 — A Use-After-Free vulnerability in WebRTC, which could be exploited to corrupt memory and achieve remote code execution through a maliciously crafted web page.
  • CVE-2026-9110 — An Inappropriate Implementation flaw in the UI layer, which could allow attackers to bypass security restrictions or spoof browser interface elements.

Use-after-free bugs are particularly dangerous because they allow threat actors to manipulate freed memory regions, often leading to full system compromise when successfully chained with other exploits.

High-Severity Vulnerabilities Patched

Beyond the critical bugs, Google patched nine High-severity flaws spanning multiple components:

CVE Type Component Bounty
CVE-2026-9112 Use-After-Free GPU $11,000
CVE-2026-9113 Out-of-Bounds Read GPU $3,000
CVE-2026-9114 Use-After-Free QUIC N/A
CVE-2026-9115 Insufficient Policy Enforcement Service Worker N/A
CVE-2026-9116 Insufficient Policy Enforcement ServiceWorker N/A
CVE-2026-9117 Type Confusion GFX N/A
CVE-2026-9118 Use-After-Free XR N/A
CVE-2026-9119 Heap Buffer Overflow WebRTC N/A
CVE-2026-9120 Use-After-Free WebRTC N/A

CVE-2026-9112 and CVE-2026-9113 were responsibly disclosed by an external researcher identified as c6eed09fc8b174b0f3eebedcceb1e792, earning a combined $14,000 in bug bounties.

Other Medium-Severity Fixes

Google also patched five Medium-severity issues, including out-of-bounds reads in GPU (CVE-2026-9121, CVE-2026-9122 — credited to David Korczynski of Adalogics and the same external researcher), a heap buffer overflow in Chromecast (CVE-2026-9123), insufficient input validation (CVE-2026-9124), and a use-after-free in DOM (CVE-2026-9126).

Mitigations

Google notes that bug details will remain restricted until most users have received the patch, reducing the risk of exploitation during the rollout window.

Users and administrators should take the following steps immediately:

  • Navigate to chrome://settings/help and confirm the browser version is 148.0.7778.178 or higher
  • Restart Chrome to apply any pending updates
  • Enterprise administrators should force-deploy the update via policy management tools
  • Monitor Chrome release notes and CISA advisories for any active exploitation indicators

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Authorities Have Taken Down “First VPN” Used in Ransomware Attacks

Next Post

Indian Student Data Weaponized for Phishing & Financial

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Windows Kernel Vulnerability Lets Attackers Modify Memory
May 27, 2026
GitHub Enterprise Server 3.20.3 Fixes Released With
May 27, 2026
CISA Warns: LiteSpeed cPanel Plugin Fl Vulnerability Exploited
May 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us