Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Malicious npm Campaign Steals SSH Keys & Cloud Credentials
June 12, 2026
Home/CyberSecurity News/Google Patches Critical Chrome Vulnerabilities Allowing Code Execution
CyberSecurity News

Google Patches Critical Chrome Vulnerabilities Allowing Code Execution

Google has released a new security update for its Chrome browser, patching 28 vulnerabilities, including several critical flaws that could allow attackers to achieve remote code execution on affected...

Sarah simpson
Sarah simpson
June 12, 2026 3 Min Read
8 0

Google has released a new security update for its Chrome browser, patching 28 vulnerabilities, including several critical flaws that could allow attackers to achieve remote code execution on affected systems.

The latest Stable channel update upgrades Chrome to version 149.0.7827.114/.115 on Windows and macOS, and to 149.0.7827.114 on Linux.

The rollout is being deployed gradually and is expected to reach users over the coming days and weeks. Google has also published a detailed changelog outlining all modifications included in this release.

Critical Vulnerabilities Enable Code Execution

Among the most serious issues patched are multiple critical memory-corruption vulnerabilities.

These include several use-after-free flaws in core components, including Core, DigitalCredentials, and WebMIDI, identified as CVE-2026-12007, CVE-2026-12008, and CVE-2026-12011.

Such vulnerabilities occur when memory is improperly managed, allowing attackers to manipulate freed memory regions.

Google also addressed a critical heap buffer overflow vulnerability in the GPU component, tracked as CVE-2026-12010, along with an insufficient validation of untrusted input issue in the Accessibility component, identified as CVE-2026-12009.

These flaws could be exploited by convincing users to visit specially crafted web pages, potentially enabling arbitrary code execution and leading to full system compromise.

In addition to the critical vulnerabilities, the update resolves numerous high-severity issues affecting a wide range of Chrome components.

Several of these involve use-after-free vulnerabilities across Network, Media, Autofill, GPU, Video, and Views modules. These bugs can lead to memory corruption and are often leveraged in exploit chains.

Other high-severity issues include out-of-bounds read and write vulnerabilities in components such as Codecs, Video, and VideoCapture, which could allow attackers to access or manipulate memory in unintended ways.

A heap buffer overflow vulnerability in the GPU component further increases the risk of exploitation. The update also fixes multiple instances of insufficient validation of untrusted input in DevTools, Extensions, Network, and Linux Toolkit Theming.

In addition, Google addressed improper policy enforcement issues in DevTools and Headless mode, as well as a race condition vulnerability in Safe Browsing.

These weaknesses could potentially be abused to bypass security restrictions or interfere with browser protections.

Although Google has not confirmed whether these vulnerabilities are being actively exploited in the wild, the presence of multiple memory-related flaws significantly raises the likelihood of exploitation.

Attackers frequently target such vulnerabilities through malicious websites, exploit kits, or compromised advertising networks.

To minimize risk, Google has restricted access to detailed vulnerability information until a majority of users have installed the update.

This approach helps prevent attackers from analyzing patches to develop exploits before systems are secured. Google credited both internal security teams and external researchers for identifying and reporting these vulnerabilities.

The company also emphasized the role of advanced detection tools such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL in discovering and mitigating security flaws during development.

Users are strongly encouraged to update Chrome immediately to the latest version to protect against potential threats. While automatic updates are typically enabled, users can manually verify their browser version through the Chrome settings panel.

Organizations should prioritize patch deployment across all systems to reduce exposure and prevent possible exploitation.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Palo Alto PAN-OS Vulnerability Allows Root Command Execution

Next Post

Microsoft Outlook and Word Vulnerabilities Allow Attackers to

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Arch Linux AUR Supply Chain Attack Deploys Infostealers
June 12, 2026
Critical LangGraph Vulnerability Gives Attackers Full Server Control
June 12, 2026
SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us