Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
152 Chrome Extensions Maliciously Hide Ad Tracking
June 14, 2026
Maine AG Takes Data Breach Portal Offline After Fake
June 14, 2026
Agentjacking Attack Hijacks AI Coding Agent for Mal
June 13, 2026
Home/CyberSecurity News/Chrome Patches 429 Vulnerabilities, 2 Including Critical
CyberSecurity News

Chrome Patches 429 Vulnerabilities, 2 Including Critical

Google has issued an urgent stable update for Chrome, addressing a substantial 429 vulnerabilities. This release, Chrome 149.0.7827.x, includes patches for 22 critical flaws affecting users across...

Jennifer sherman
Jennifer sherman
June 8, 2026 3 Min Read
16 0

Google has issued an urgent stable update for Chrome, addressing a substantial 429 vulnerabilities. This release, Chrome 149.0.7827.x, includes patches for 22 critical flaws affecting users across Windows, macOS, Linux, and Chrome for iOS. All users are strongly advised to update promptly.

Google has promoted Chrome 149.0.7827.x to the stable channel with one of the largest security patch bundles seen in a single release cycle, covering 429 distinct vulnerabilities.

The fixes span the browser engine, graphics and GPU layers, media pipeline, UI, networking stack and Chrome‑specific features such as Autofill, Password Manager, DevTools, WebView and Chrome for iOS.

As usual, Google is limiting access to detailed issue descriptions and bug tracker entries until most users have updated, to reduce the likelihood of threat actors weaponizing them.

This release targets desktop builds on Windows, Mac and Linux, alongside coordinated fixes for Chrome on iOS, Chromecast and other ecosystem components that share core code.

For enterprises, the update represents a broad hardening step across multiple devices, where Chrome is often the first line of defense against untrusted web content, SaaS apps, and cloud control planes.

Chrome Patches 429 Vulnerabilities

Of the 429 bugs, 22 are classified as critical, many of which are rooted in memory‑safety defects in graphics, GPU, and core browser components.

These include out‑of‑bounds read and write issues in ANGLE (such as CVE‑2026‑10881 and CVE‑2026‑10883) and a stack buffer overflow in the GPU stack (CVE‑2026‑10898).

Multiple use‑after‑free conditions across Network, Chromecast, Cast Streaming, Chromoting, Printing, FileSystem, GFX, Ozone and Chrome for iOS.

Such flaws are prime candidates for remote code execution, sandbox escape, and privilege escalation when combined with weaknesses in the renderer or JavaScript engine.

The presence of several critical issues affecting Chrome for iOS and casting components also raises the risk profile for users and organizations that rely on Chrome in multi‑device workflows, meeting rooms and hybrid work environments.

Beyond the critical set, Google has addressed a substantial number of high‑severity vulnerabilities, many of which are directly reachable from web content.

These include type confusion and implementation bugs in V8, use-after-free in WebRTC, Network, WebAuthentication, Audio, UI, and FileSystem, as well as integer overflows in Dawn, DevTools, Media, and V8.

Collectively, they provide building blocks for exploit chains that can pivot from browser compromise into persistence or lateral movement inside enterprise networks.

Hundreds of medium‑severity issues focus on insufficient validation of untrusted input, policy bypasses, uninitialized use, and incorrect security UI.

CVE ID Component Bug class
CVE‑2026‑10881 ANGLE Out‑of‑bounds read/write
CVE‑2026‑10882 Network Use‑after‑free
CVE‑2026‑10883 ANGLE Out‑of‑bounds write
CVE‑2026‑10884 Chromecast Use‑after‑free
CVE‑2026‑10885 Chrome for iOS Use‑after‑free
CVE‑2026‑10886 FileSystem Use‑after‑free
CVE‑2026‑10887 Chromoting Use‑after‑free
CVE‑2026‑10888 Cast Streaming Use‑after‑free
CVE‑2026‑10889 ANGLE Out‑of‑bounds read
CVE‑2026‑10890 Cast Use‑after‑free
CVE‑2026‑10891 GFX Use‑after‑free
CVE‑2026‑10892 GPU Out‑of‑bounds write
CVE‑2026‑10893 Chromoting Use‑after‑free
CVE‑2026‑10894 Printing Use‑after‑free
CVE‑2026‑10895 Ozone Use‑after‑free
CVE‑2026‑10896 Chrome for iOS Use‑after‑free
CVE‑2026‑10897 GPU Out‑of‑bounds write
CVE‑2026‑10898 GPU Stack buffer overflow
CVE‑2026‑10899 Ozone Use‑after‑free
CVE‑2026‑10900 Passwords Use‑after‑free
CVE‑2026‑10901 Passwords Use‑after‑free
CVE‑2026‑10902 Ozone Use‑after‑free

Data‑handling weaknesses in components such as Password Manager, WebView, CSS, SVG, USB, GPU, WebRTC, Safe Browsing, and others.

While individually less severe, these bugs align well with modern tracking and exploitation techniques, from leaking sensitive state to bypassing consent prompts or eroding isolation boundaries in complex deployments.

The update also delivers numerous low‑severity fixes in peripheral but important components, including TabStrip, Navigation, DevTools, Content Settings, Safe Browsing, Extensions, Enterprise features and various UI elements.

These issues often relate to incorrect security UI, insufficient policy enforcement and subtle edge‑case behavior that, if left unpatched, could still be abused in targeted scenarios or combined with higher‑impact bugs.

Google credits a broad community of independent researchers, academic labs and internal teams, emphasizing the role of sanitizers and fuzzing frameworks such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer and AFL in surfacing many of the memory‑safety defects.

Even with this proactive detection, the sheer volume of vulnerabilities in this release underlines the ongoing intensity of browser security work and the importance of timely patch adoption.

Given the concentration of critical and high‑severity vulnerabilities in components such as ANGLE, GPU, Network, Password Manager, WebRTC, and Chrome for iOS, organizations and end users should prioritize deploying Chrome 149.0.7827.x without delay.

Security teams should enforce automatic updates wherever possible, push the new build fleet‑wide through management tooling, verify coverage, and prepare to track any exploitation attempts tied to these CVEs once full technical details are made public.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVEExploitPatchSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

OWASP’s New AI Security Report Empowers Security Pros

Next Post

WhatsApp Stops NSO Pegasus Spyware Attacks on Users

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Government Directive Blocks Anthropic Fable 5 & Mythos Access
June 13, 2026
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us