Chrome Security
The latest Chrome Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Chrome to 149+ now: GPU bug lets renderer breach leak memory.
Google has published CVE-2026-11045, a medium-severity vulnerability in the Chrome GPU process that could allow an attacker who has already compromised the renderer to read sensitive memory contents....
Chrome for Android Patch 149.0.7827.53 Fixes High-Severity UI Spoofing Bug CVE-2026-10984
Google has patched a high-severity vulnerability in Chrome for Android that could allow a remote attacker to spoof user-interface elements, potentially tricking users into revealing sensitive...
Chrome’s ANGLE Graphics Bug (CVE-2026-7903) Could Allow Remote PC Hijacking – Patch Immediately
Google disclosed a critical integer overflow vulnerability in Chrome’s ANGLE graphics layer on Tuesday, warning that attackers could exploit it to execute arbitrary code on Windows and macOS...
Chrome 148 Patches High-Severity DOM Use-After-Free — What Windows and Edge Users Must Do
On May 6, 2026, Google shipped Chrome 148 to the stable channel, and buried within its more than 100 security fixes is a vulnerability that every Windows user—whether they run Chrome or...
Patch Chrome Now: CVE-2026-7925 Fixes High-Severity Privilege Escalation
Google has rolled out an urgent update for Chrome on Windows to address CVE-2026-7925, a high-severity use-after-free vulnerability in the Chromoting feature that could allow a local attacker to...
CVE-2026-7935: Chrome UI Spoofing via Speech Component Fixed in Version 148+
Google has patched a medium-severity vulnerability in Chrome's Speech component that could allow attackers to spoof the browser's user interface. The flaw, tracked as CVE-2026-7935, was disclosed on...
Google Patches Critical Chrome UXSS Bug Allowing Script/HTML Injection
Google has assigned CVE-2026-7939 to a freshly patched universal cross-site scripting (UXSS) vulnerability in Chrome’s built‑in Sanitizer API. The medium‑severity flaw, disclosed on May 6,...
Chrome 148 Patches CVE-2026-7945 COOP Flaw Bypassing Site Isolation
Google and Microsoft jointly disclosed CVE-2026-7945 on May 6, 2026, a medium-severity vulnerability in Chromium’s handling of the Cross-Origin-Opener-Policy (COOP) that puts site isolation at...
Chrome Navigation Use-After-Free Flaw Demands Immediate Windows Update
Google pushed out an urgent Chrome update on May 6, 2026, patching a use-after-free vulnerability in the browser’s Navigation component that carries a tangible risk of sandbox escape. Tracked as...
Chrome 148 and Edge Patch Use-After-Free Flaw Exploitable via Malicious Extensions
On May 6, 2026, Google shipped Chrome 148.0.7778.96 to the stable channel, closing a use-after-free vulnerability tracked as CVE-2026-7976. The flaw sits in Chromium’s Views component—the...
Chrome 148.0.7778.96 Patches Canvas Same-Origin Bypass—Here’s What to Do
Google released Chrome 148 on May 5, 2026, patching a medium-severity security flaw in the browser’s Canvas component that could let a malicious website bypass the same-origin policy and read pixel...
Chrome 148 Patches High-Severity WebRTC CVE-2026-7987 on Windows
Google has issued an urgent patch for Chrome on Windows, fixing a use-after-free vulnerability in the WebRTC component that could allow remote code execution within the browser’s sandbox. Disclosed...