Google Fixes 26 Chrome Vulnerabilities, Including 2 Critical Use-After-Free Flaws

Google has released Chrome 152.0.7977.75/.76 for Windows and macOS and Chrome 152.0.7977.75 for Linux, addressing 26 security vulnerabilities across the browser.

The update includes two critical use-after-free flaws affecting Shared Tab Groups and WebGL, making prompt installation important for both individual and enterprise users.

The Stable-channel update is rolling out gradually over the coming days and weeks. Google has not disclosed whether any of the flaws are being actively exploited in the wild.

However, the presence of critical memory-safety vulnerabilities means attackers could potentially use specially crafted web content to crash Chrome or gain control within the browser process.

Google Fixes 26 Chrome Vulnerabilities

The two critical issues are tracked as CVE-2026-84353 and CVE-2026-84352. CVE-2026-84353 is a use-after-free vulnerability in Shared Tab Groups. At the same time, CVE-2026-84352 affects WebGL, Chrome’s browser technology for rendering interactive 2D and 3D graphics.

A use-after-free bug occurs when software continues to access memory after it has been released. If an attacker can manipulate that memory, the flaw may lead to memory corruption, browser crashes, information disclosure, or code execution.

WebGL bugs are particularly significant because they can be reached through web applications, advertisements, or malicious websites that use graphics-related browser functions.

Google also fixed several high-severity vulnerabilities. These include CVE-2026-84354, an incorrect authorization flaw in FileSystem, CVE-2026-84359, an information leak in Skia; and CVE-2026-84357, an improper input-validation bug in the Omnibox component.

Other high-severity issues include use-after-free vulnerabilities in Proxy, Browser, and Dawn, identified as CVE-2026-84324, CVE-2026-84349, and CVE-2026-84333.

The update also resolves CVE-2026-84326, an uninitialized-resource issue in the V8 JavaScript engine, and CVE-2026-84351, a GPU buffer-overflow vulnerability.

CVESeverityComponentVulnerability
CVE-2026-84353CriticalShared Tab GroupsUse-after-free
CVE-2026-84352CriticalWebGLUse-after-free
CVE-2026-84354HighFileSystemIncorrect authorization
CVE-2026-84359HighSkiaInformation leak
CVE-2026-84357HighOmniboxImproper input validation
CVE-2026-84324HighProxyUse-after-free
CVE-2026-84349HighBrowserUse-after-free
CVE-2026-84326HighV8Uninitialized resource
CVE-2026-84333HighDawnUse-after-free
CVE-2026-84351HighGPUBuffer overflow
CVE-2026-84325HighDataTransferImproper input validation
CVE-2026-84328MediumFileSystemMissing authorization
CVE-2026-84347MediumWebRTCUse-after-free
CVE-2026-84323MediumFileSystemMissing authorization
CVE-2026-84355MediumNavigationIncorrect authorization
CVE-2026-84358MediumDownloadsImproper privilege management
CVE-2026-84332MediumSiteSettingsIncorrect authorization
CVE-2026-84330MediumFullScreenUI misrepresentation
CVE-2026-84334MediumChromotingIncorrect authorization
CVE-2026-84348MediumMediaCaptureInformation leak
CVE-2026-84335MediumTabStripIncorrect authorization
CVE-2026-84327LowAutofillIncorrect authorization
CVE-2026-84329LowCredentialProviderConfused deputy
CVE-2026-84356LowFullScreenUI misrepresentation
CVE-2026-84350LowTabStripUse-after-free
CVE-2026-84331LowActorIncorrect authorization

The remaining fixes cover medium- and low-severity issues in components including WebRTC, Downloads, Navigation, SiteSettings, FullScreen, Chromoting, MediaCapture, TabStrip, Autofill, CredentialProvider, and Actor.

Several FileSystem authorization issues were also patched. Google said it may restrict access to bug reports and technical details until most users have installed the update.

This practice helps reduce the risk that attackers could weaponize publicly available vulnerability information before systems are patched.

The company credited internal teams and external security researchers for reporting vulnerabilities during the development cycle.

Google also relies on security testing technologies such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL to identify bugs before they reach the Stable channel.

Users can check for updates by opening Chrome, navigating to Settings, selecting About Chrome, and allowing the browser to download the latest version. Organizations should verify that managed endpoints receive Chrome 152.0.7977.75 or later as the rollout progresses.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Google Fixes 26 Chrome Vulnerabilities, Including 2 Critical Use-After-Free Flaws appeared first on Cyber Security News.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Leave a Reply

Your email address will not be published. Required fields are marked *

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading