Google Chrome Patches 151 Vulnerabilities, 22 Critical
Key Takeaways Google has released a critical security update for its Chrome browser, addressing 151 vulnerabilities. Twenty-two of these patched flaws are rated as critical, impacting core components...
Key Takeaways
- Google has released a critical security update for its Chrome browser, addressing 151 vulnerabilities.
- Twenty-two of these patched flaws are rated as critical, impacting core components across Windows, macOS, and Linux.
- The vulnerabilities could lead to severe consequences, including remote code execution or sandbox escapes, if exploited.
- Users are strongly advised to update their Chrome browsers immediately to the latest stable version.
Google has rolled out a substantial security update for its Chrome browser, tackling a total of 151 security vulnerabilities. Among these, 22 are classified as critical, posing significant risks to users across Windows, macOS, and Linux operating systems. These high-severity flaws affect fundamental elements of the browser, including its graphics rendering, networking capabilities, media processing, and user interface.
Table Of Content
The stable channel of Chrome has been updated to version 148.0.7778.216/217 for Windows, 148.0.7778.215/216 for macOS, and 148.0.7778.215 for Linux. Google indicates that this update will be progressively distributed to users over the coming days and weeks.
While a comprehensive list of code changes between builds 148.0.7778.180 and 148.0.7778.217 is accessible via the Chromium source log, Google is withholding detailed information about the specific bugs. This strategic delay in disclosure is intended to prevent malicious actors from exploiting the vulnerabilities before a majority of users have applied the necessary patches.
Google acknowledged the contributions of both its internal security teams and external researchers in identifying these issues during the browser’s development lifecycle. The company highlighted that many vulnerabilities were detected and remediated before they could reach the stable release branch, attributing this success partly to its extensive use of advanced security tools such as sanitizers, fuzzers, and control-flow integrity mechanisms designed to uncover memory corruption and undefined behavior at scale.
Extensive Vulnerability Patching in Chrome
Of the 151 vulnerabilities addressed, 22 are deemed critical, and several have already resulted in substantial bug bounty payouts. These critical issues, if exploited, could facilitate severe attacks such as sandbox escapes, remote code execution, or data corruption, typically by luring a victim to a specially crafted malicious webpage.
Key externally reported vulnerabilities include:
- CVE-2026-9872: An out-of-bounds write flaw in the GPU process, reported by cinzinga, with a reward of 43,000 USD.
- CVE-2026-9873: A use-after-free vulnerability in the Network component, also reported by cinzinga, earning 43,000 USD.
- CVE-2026-9874: A use-after-free issue in Dawn, reported anonymously, with a reward of 11,000 USD.
- CVE-2026-9875: An out-of-bounds read vulnerability in WebGL, reported anonymously, receiving 5,000 USD.
The majority of critical fixes, however, were identified by Google’s internal teams. These predominantly target the browser’s graphics and rendering stack, encompassing components such as ANGLE, Skia, WebGL, Dawn, XR, Bluetooth, UI, and the core browser infrastructure. The identified issues include common exploit primitives like use-after-free errors, heap buffer overflows, integer overflows, and insufficient validation of untrusted input.
Beyond the critical vulnerabilities, Google also patched numerous high-severity flaws across various components, including DOM, Accessibility, Site Isolation, WebCodecs, PDF/PDFium, WebRTC, Passwords, WebAppInstalls, Media, and USB. These encompass additional use-after-free conditions, out-of-bounds reads and writes, race conditions, and uninitialized memory usage. While many were reported internally, some were credited to researchers from organizations such as Mozilla, Microsoft, and OpenAI.
Medium-severity vulnerabilities were also addressed, covering further integer overflows and insufficient input validation in components like ANGLE, Skia, USB, V8, and Headless. These also led to significant, albeit smaller, bounty payments.
Google reiterated that many of these bugs were discovered through automated testing tools, including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL. This underscores the crucial role of automated testing in continually reducing the attack surface of modern browsers.
In adherence to standard security practices, details for some bugs will remain private, particularly if they affect widely used third-party libraries that have not yet released their own patches.
What You Should Do
- Update Immediately: Enterprise defenders and individual users are strongly advised to update their Google Chrome browsers to the latest stable build (version 148.0.7778.x) as soon as it becomes available for their respective platforms.
- Enable Automatic Updates: Ensure that automatic updates are enabled for Chrome to receive security patches promptly.
- Consider Faster Release Channels: Organizations requiring earlier access to patches may consider switching to a faster release channel for Chrome.
- Report New Issues: Google encourages anyone who discovers new security vulnerabilities to report them via the public bug tracker.
- Seek Support: For assistance with update or deployment issues, users can consult the Chrome community help forum.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.