Chrome Security
The latest Chrome Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome 149 Patch Nixes High-Risk Site Isolation Bypass, CVE-2026-13034
Google has patched a high-severity security flaw in Chrome that allows attackers who have already compromised the renderer process to bypass the browser's critical site isolation defenses. Tracked as...
Google Patches CVE-2026-13021: DBSC Flaw Allowed Same-Origin Bypass in Chrome
Google has shipped an urgent security fix for a vulnerability in Chrome that undermined one of the web’s most fundamental security boundaries. Tracked as CVE-2026-13021, the flaw was rooted in the...
Google Rushes Chrome 149 Patch for High-Severity Autofill Zero-Day Exploitable via Renderer Breach
Google has rolled out Chrome 149.0.7827.197 for Windows to close a freshly disclosed high-severity hole in the browser’s Autofill system—a bug that a remote attacker can weaponize after first...
Google Fixes High-Severity Chrome Flaw That Could Allow Mac Sandbox Escape
Google has shipped an emergency fix for a high-severity bug in Chrome that could have allowed attackers to break out of the browser’s protective sandbox on macOS. Tracked as CVE-2026-11655, the...
Chrome's Latest Sandbox Escape Flaw CVE-2026-11700 Demands Immediate Patching on Windows
A single memory safety mistake in Chrome’s tracing subsystem has handed attackers a rare and dangerous escape hatch from the browser’s most critical defense. Google disclosed CVE-2026-11700 on...
Mac Users at Risk: Google Fixes Critical Bluetooth Zero-Click Exploit in Chrome 149
Google has patched a high-severity use-after-free vulnerability in Chrome’s Bluetooth implementation on macOS, tracked as CVE-2026-11699, that could allow an attacker to execute arbitrary code...
Google Chrome Emergency Fix for CVE-2026-11697 Closes High-Severity Sandbox Escape
Google has rushed out an emergency security update for its Chrome browser to plug a high-severity sandbox escape vulnerability tracked as CVE-2026-11697. The flaw, which affects Chrome on Windows,...
Chrome 149 Fixes High-Severity Cross-Origin Leak in New Tab Page (CVE-2026-11691)
Google has rolled out a critical update to Chrome 149, patching a high-severity vulnerability in the browser’s New Tab Page (NTP) that could let attackers who have already hijacked the renderer...
High-Severity SVG Flaw in Google Chrome Patched: CVE-2026-11688 Enables Sandboxed Code Execution
Google has released an emergency security update for its Chrome browser to address a high-severity vulnerability in the browser's SVG rendering engine. Tracked as CVE-2026-11688, the flaw allows a...
Google Patches High-Severity Chrome Flaw Leaking Cross-Origin Data (CVE-2026-11684)
Google released a critical security update for Chrome on June 8, 2026, addressing a high-severity vulnerability tracked as CVE-2026-11684. The flaw, nestled within Chromium’s Network component,...
Chrome 149 Fixes Critical WebGPU Sandbox Escape, NVD CPE Delay Exposes Detection Gaps
Google patched a high-severity sandbox escape vulnerability in its Chrome browser on June 8, 2026, fixing a flaw in the Dawn WebGPU graphics component that potentially allowed attackers to break out...
Urgent Chrome 149 Update Patches High-Risk Use-After-Free in InterestGroups Component
Google has released an urgent security update for Chrome, patching a high-severity use-after-free vulnerability in the browser’s InterestGroups component. Tracked as CVE-2026-11673, the flaw could...