Google Chrome Update Fixes 26 Security Flaws Including Two Critical Use-After-Free Bugs

Google has released a new Stable Channel update for Chrome desktop that patches 26 security vulnerabilities, including two critical-severity use-after-free flaws affecting Shared Tab Groups and WebGL.

The update is rolling out as Chrome version 152.0.7977.75/.76 for Windows and macOS, and version 152.0.7977.75 for Linux.

Users and enterprise administrators should apply the update promptly, particularly because the release addresses multiple memory-safety issues in browser components that process web content.

Google Chrome Update Fixes 26 Security Flaws

The most severe vulnerabilities are tracked as CVE-2026-84353 and CVE-2026-84352. CVE-2026-84353 is a critical use-after-free issue in Shared Tab Groups, while CVE-2026-84352 affects WebGL, Chrome’s interface for rendering interactive 2D and 3D graphics through the browser.

Use-after-free vulnerabilities occur when software continues to access memory after it has been released.

In browser attack chains, such memory-corruption bugs can potentially be leveraged to cause crashes, leak information, or execute attacker-controlled code, depending on exploitability and the effectiveness of Chrome’s layered mitigations.

Eleven additional flaws received a high-severity rating. These include use-after-free bugs in Chrome’s Proxy, Browser, and Dawn components; an uninitialized resource issue in the V8 JavaScript engine; and a GPU buffer overflow.

Google also fixed authorization and input-validation flaws affecting FileSystem, the Omnibox, and DataTransfer.

The patch set further includes medium-severity weaknesses in WebRTC, Downloads, Navigation, SiteSettings, Chromoting, MediaCapture, TabStrip, and FullScreen.

Several low-severity issues address authorization defects, UI misrepresentation, a confused-deputy condition in CredentialProvider, and another use-after-free flaw in TabStrip.

CVEAffected ComponentVulnerability Type
CVE-2026-84353Shared Tab GroupsUse-after-free
CVE-2026-84352WebGLUse-after-free
CVE-2026-84354FileSystemIncorrect authorization
CVE-2026-84359SkiaInformation leak
CVE-2026-84357OmniboxImproper input validation
CVE-2026-84324ProxyUse-after-free
CVE-2026-84349BrowserUse-after-free
CVE-2026-84326V8Uninitialized resource
CVE-2026-84333DawnUse-after-free
CVE-2026-84351GPUBuffer overflow
CVE-2026-84325DataTransferImproper input validation
CVE-2026-84328FileSystemMissing authorization
CVE-2026-84347WebRTCUse-after-free
CVE-2026-84323FileSystemMissing authorization
CVE-2026-84355NavigationIncorrect authorization
CVE-2026-84358DownloadsImproper privilege management
CVE-2026-84332SiteSettingsIncorrect authorization
CVE-2026-84330FullScreenUI misrepresentation
CVE-2026-84334ChromotingIncorrect authorization
CVE-2026-84348MediaCaptureInformation leak
CVE-2026-84335TabStripIncorrect authorization
CVE-2026-84327AutofillIncorrect authorization
CVE-2026-84329CredentialProviderConfused deputy
CVE-2026-84356FullScreenUI misrepresentation
CVE-2026-84350TabStripUse-after-free
CVE-2026-84331ActorIncorrect authorization

Google has not stated that any of the 26 vulnerabilities are being actively exploited in the wild.

However, technical details and issue links may remain restricted until most users have deployed the fix, a standard practice intended to reduce the chance of attackers weaponizing newly disclosed bugs before patch adoption is widespread.

Chrome users can update by navigating to Settings → About Chrome, allowing the browser to download the latest release, and restarting it to complete installation.

Organizations should verify the deployed version across managed Windows, macOS, and Linux endpoints and prioritize remediation on systems exposed to untrusted web content.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories