Google Chrome Update Fixes 12 Vulnerabilities That Could Enable Browser Attacks

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

Google has rolled out a new Stable channel update for Chrome, patching 12 security vulnerabilities, including nine rated “High” severity. The update brings Chrome to version 150.0.7871.181/.182 for Windows and Mac, and 150.0.7871.181 for Linux, with the rollout expected to reach all users over the coming days and weeks.

Several of the fixed flaws could allow attackers to trigger memory corruption, execute arbitrary code, or bypass security validations, making this update a priority patch for both individual users and enterprise IT teams.

Chrome Update Fixes 12 Vulnerabilities

The update addresses flaws across multiple Chrome components, including V8, ANGLE, Skia, GPU, UI, Extensions, and Chromecast. Notable fixes include:

CVE ID Severity Vulnerability Type Component Reported By Date Reported
CVE-2026-16413 High Out of bounds write ANGLE Google 2026-05-28
CVE-2026-16414 High Insufficient validation of untrusted input Chromecast Google 2026-05-28
CVE-2026-16415 High Insufficient validation of untrusted input Extensions Google 2026-06-02
CVE-2026-16416 High Integer overflow Chromecast Google 2026-06-05
CVE-2026-16417 High Uninitialized use Skia Google 2026-06-08
CVE-2026-16418 High Stack buffer overflow V8 Google 2026-06-10
CVE-2026-16419 High Out of bounds read and write ANGLE Google 2026-06-13
CVE-2026-16420 High Type Confusion WebAudio XBOW (triaged by Brendan Dolan-Gavitt) 2026-06-26
CVE-2026-16421 High Inappropriate implementation WebAudio XBOW (triaged by Brendan Dolan-Gavitt) 2026-06-26
CVE-2026-16422 High Insufficient validation of untrusted input Certificate Google 2026-07-10
CVE-2026-16423 High Use after free UI Google 2026-07-14
CVE-2026-16424 High Use after free GPU Google 2026-07-14

Two of these bugs, CVE-2026-16420 and CVE-2026-16421, were discovered by XBOW, an autonomous AI-powered security research system, and triaged by researcher Brendan Dolan-Gavitt. Each earned a $500 bounty reward.

The remaining ten vulnerabilities were identified internally by Google’s own security teams between late May and mid-July 2026.

Vulnerabilities involving type confusion, use-after-free, and buffer overflows are particularly dangerous because they affect how Chrome manages memory.

If exploited, attackers could potentially execute malicious code, crash the browser, or gain unauthorized access to system resources simply by getting a victim to visit a compromised or malicious webpage.

The V8 stack buffer overflow (CVE-2026-16418) and GPU/UI use-after-free bugs (CVE-2026-16423, CVE-2026-16424) stand out as high-risk since they touch core rendering and JavaScript execution components, common targets in real-world browser exploit chains.

Google credits much of its bug-detection success to automated tools like AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL.

These tools help catch memory-safety issues before they ever reach the Stable channel, reflecting Chrome’s layered approach to proactive vulnerability discovery.

Google has withheld detailed bug reports and links for several issues, a standard practice while a majority of users update to the patched version, or while a fix for a shared third-party library remains outstanding.

What Users Should Do

Given the volume of High-severity fixes in this release, users should update Chrome immediately rather than waiting for the automatic rollout. To manually update:

  1. Open Chrome and click the three-dot menu in the top-right corner.
  2. Navigate to Help > About Google Chrome.
  3. Let Chrome check for updates and install the latest version automatically.
  4. Restart the browser to apply the update.

Enterprises managing Chrome deployments across multiple endpoints should prioritize pushing this update through their device management systems, given the presence of multiple High-severity memory corruption bugs that could be chained together in sophisticated attacks.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment