Google Chrome 113.0.5672.126 Patches 42 Vulnerabilities, 3 Critical
Key Takeaways Google has released a critical security update, Chrome version 153, addressing 42 vulnerabilities. Three of the patched flaws are rated Critical, with the potential for severe impact....
Key Takeaways
- Google has released a critical security update, Chrome version 153, addressing 42 vulnerabilities.
- Three of the patched flaws are rated Critical, with the potential for severe impact.
- The update is rolling out for Windows, macOS, and Linux, and users are urged to update immediately.
- A wide range of browser components are affected, highlighting the complexity of modern browser security.
Google has issued a significant security update for its Chrome browser, version 153, which addresses a total of 42 security vulnerabilities. Among these, three have been classified as Critical, underscoring the urgency for users to update their installations. The stable channel is being updated to 153.0.8010.47/.48 for Windows and macOS users, and 153.0.8010.47 for Linux, with the rollout expected to complete over the coming days and weeks.
Table Of Content
Critical Vulnerabilities Addressed
The three Critical flaws include two use-after-free vulnerabilities and one out-of-bounds read. Specifically, CVE-2026-91721, a use-after-free bug in Chrome’s Internals component, was reported by researcher xinyang. Another use-after-free vulnerability, CVE-2026-91749, affects Workers and was discovered by WinD39–Huynh Dinh Vu. The third critical flaw, CVE-2026-91726, is an out-of-bounds read within WebGL, which Google identified internally.
Use-after-free vulnerabilities are a dangerous class of memory corruption bugs. They occur when a program attempts to access memory that has already been deallocated, leading to unpredictable behavior such as crashes, information disclosure, or, in severe cases, arbitrary code execution. The specific impact depends on factors like the affected process, existing security mitigations, and available exploit primitives.
Similarly, out-of-bounds read vulnerabilities, like the one found in WebGL, can allow an attacker to read data from memory locations outside of an intended buffer. Google has not yet disclosed specific exploit scenarios or detailed technical information for these three Critical vulnerabilities, nor has it indicated that any of the 42 patched issues are currently under active exploitation.
Extensive High-Severity Patches
Beyond the critical flaws, Chrome 153 also resolves 27 high-severity vulnerabilities across various sensitive browser components. These encompass a broad spectrum of issues, including multiple use-after-free bugs impacting Input, Skia, DOM, WebAppInstalls, Core, Auth, DigitalCredentials, PDF, and V8. Type confusion vulnerabilities were also patched in Compositing, CacheStorage, and ServiceWorker. Furthermore, the update addresses integer overflows in V8 and Compositing, race conditions in Core, PlatformIntegration, Extensions, and Network, and an out-of-bounds write in ServiceWorker.
The update also rectifies authorization and validation weaknesses, demonstrating the wide scope of security challenges in modern browsers. Patches include corrections for authorization issues in Core, Android, and WebUI, an incorrect reference-resolution flaw in Extensions, uninitialized-resource bugs in ANGLE and Skia, and improper state validation in Skia. This extensive list underscores the inherent complexity in securing a browser that manages diverse elements like graphics, scripts, extensions, documents, credentials, and untrusted web content within an interconnected process architecture.
Medium and Low-Severity Fixes
The remaining patches cover ten Medium-severity vulnerabilities and one Low-severity issue. These include authorization failures, observable discrepancies in Fonts and CSS, improper input validation in ANGLE, incomplete cleanup in GetUserMedia, and another use-after-free bug in Input. The sole Low-severity flaw, CVE-2026-91719, involves a code injection vulnerability in XML, reported by Zabith Mohammed.
Google has also acknowledged and rewarded several external researchers for their contributions. Hafiizh received $1,500 for reporting CVE-2026-91724, a high-severity use-after-free vulnerability in Input. Jihyeon Jeong of Seoul National University’s Compsec Lab was awarded $1,000 for CVE-2026-91728, a high-severity integer overflow in V8. Rewards for several other externally reported findings are still pending, indicated as “TBD” in Google’s advisory.
Detailed bug links and technical specifics may remain restricted until a majority of users have applied the patches. This practice helps to limit attackers’ access to critical information during the update deployment phase, particularly when vulnerabilities exist in shared third-party libraries.
What You Should Do
- Update Chrome Immediately: Open Chrome, navigate to “Help” > “About Google Chrome,” allow the update to install, and then click “Relaunch.” While Chrome often updates in the background, a restart is essential to apply the new version.
- Verify Installation: Confirm that your browser is running version 153.0.8010.47/.48 on Windows/macOS or 153.0.8010.47 on Linux. Do not solely rely on automatic updates to ensure the patched binary is active.
- Enterprise Administrators: Expedite the deployment of this update across all managed endpoints. Review devices that may be held back by update policies or awaiting restarts. Utilize Group Policy for centralized management on eligible Windows devices, and regularly check applied settings at
chrome://policy. Identify and address any duplicate installations or alternate Chrome channels. - Enforce Restarts: Ensure that users have relaunched their browsers after the update has downloaded, as the patch will not take effect until a restart occurs.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.