Google has rolled out an urgent Chrome 147 security update, patching multiple high-risk vulnerabilities that could allow attackers to execute arbitrary code and fully compromise affected systems.
The update, released on April 7, 2026, is now available for Windows, Mac, and Linux users and is being deployed globally in phases.
Security experts warn that several of the flaws require no user interaction beyond visiting a malicious webpage, significantly increasing exploitation risk.
At the center of this release are two critical vulnerabilities in the WebML component, tracked as CVE-2026-5858 and CVE-2026-5859.
These flaws involve heap buffer overflow and integer overflow issues, both of which can enable remote code execution.
Google awarded $43,000 in bug bounties to researchers who responsibly disclosed these issues, highlighting their severity.
Beyond the critical bugs, Chrome 147 fixes a wide range of high-severity vulnerabilities across key components such as V8, WebRTC, Blink, Media, Skia, and ANGLE.
These include use-after-free errors, type confusion, and out-of-bounds memory access flaws. Successful exploitation could lead to browser crashes, data leaks, or full system takeover.
Google has restricted detailed technical information about these vulnerabilities to prevent threat actors from quickly developing exploits.
This coordinated disclosure approach ensures users have time to apply patches while also protecting downstream projects relying on shared libraries.
| CVE ID | Severity | Component | Vulnerability Type |
|---|---|---|---|
| CVE-2026-5858 | Critical | WebML | Heap buffer overflow |
| CVE-2026-5859 | Critical | WebML | Integer overflow |
| CVE-2026-5860 | High | WebRTC | Use-after-free |
| CVE-2026-5861 | High | V8 | Use-after-free |
| CVE-2026-5865 | High | V8 | Type confusion |
| CVE-2026-5866 | High | Media | Use-after-free |
| CVE-2026-5868 | High | ANGLE | Heap buffer overflow |
| CVE-2026-5870 | High | Skia | Integer overflow |
| CVE-2026-5872 | High | Blink | Use-after-free |
| CVE-2026-5873 | High | V8 | Out-of-bounds read/write |
In total, the update addresses dozens of vulnerabilities across severity levels, including medium and low-risk issues such as policy bypass, race conditions, and insufficient input validation.
The most concerning aspect of these flaws is their ease of exploitation. Attackers can craft malicious websites that trigger memory corruption vulnerabilities when visited.
For example, a victim clicking a phishing link could unknowingly execute attacker-controlled code in the background, leading to malware installation or credential theft.
Patch and Mitigation
Users and enterprise administrators are strongly advised to update Chrome immediately. The latest versions include:
- 147.0.7727.55 for Linux
- 147.0.7727.55/56 for Windows and Mac
To manually update:
- Open Chrome menu
- Go to Help → About Google Chrome
- Allow the browser to download and install updates
Given the active threat landscape and the critical nature of these vulnerabilities, delaying updates could expose systems to real-world attacks.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google