Chrome Security
The latest Chrome Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome CVE-2026-5914: Malicious Extensions Exploit V8 Engine for Persistent Heap Attacks
Google has disclosed CVE-2026-5914, a critical type confusion vulnerability in Chrome's V8 JavaScript engine that enables heap corruption through malicious extensions. This security flaw represents a...
Chrome 147 Update Closes WebML Memory Hole: Why Every Windows User Should Patch Now
Google released Chrome 147.0.7727.55 on April 8, 2026, plugging a memory-corruption vulnerability in the browser’s WebML component that could allow an attacker to write data outside allocated...
Update Chrome to 147 Immediately: Blink Bug CVE-2026-5913 Can Leak Private Data
Google pushed Chrome 147 to the stable channel on April 7, 2026, and with it came a fix for CVE-2026-5913—an out-of-bounds read in the Blink rendering engine that lets a remote attacker read memory...
CVE-2026-5919: Chrome WebSocket Bug Bypasses Same-Origin Policy - Microsoft Issues Security Advisory
Microsoft's Security Update Guide now documents CVE-2026-5919, a Chromium-based vulnerability that allows attackers to bypass the Same-Origin Policy through improper WebSocket validation. The flaw...
CVE-2026-5870 Skia bug in Chrome/Edge allows sandbox escape via integer overflow.
Google has disclosed CVE-2026-5870, a critical integer overflow vulnerability in the Skia graphics library affecting Chrome and Microsoft Edge. The security flaw, patched in version 147.0.7727.55,...
Microsoft Edge Enterprise Update Guide: Fix Critical WebML Heap Flaw CVE-2026-5869
Microsoft has issued comprehensive guidance for enterprise administrators following Google's disclosure of CVE-2026-5869, a critical heap buffer overflow vulnerability in the WebML component...
Critical Chrome Navigation Flaw CVE-2026-5877 Forces Emergency Microsoft Edge Patches
Google has disclosed CVE-2026-5877, a critical use-after-free vulnerability in Chrome's navigation component that enables remote code execution with sandbox escape capabilities. The vulnerability...
Chrome 147.0.7727.55 Fixes Blink Engine Flaw Enabling Fake Security Prompts
Google has patched CVE-2026-5878, a medium-severity UI spoofing vulnerability in Chrome's Blink engine that allows attackers to create deceptive security interfaces. The vulnerability affects Chrome...
CVE-2026-5882: Chrome's Fullscreen UI Spoofing Vulnerability Explained and What Windows Users Need to Know
Google's latest Chrome security update addresses CVE-2026-5882, a high-severity vulnerability that allows attackers to spoof browser UI elements in fullscreen mode. This security flaw represents a...
CVE-2026-5889 Bypasses PDF Encryption in Chrome and Edge — Update Now
A cryptographic vulnerability in the PDFium engine used by both Google Chrome and Microsoft Edge allows attackers to bypass encryption on protected PDF documents. Designated CVE-2026-5889, this flaw...
CVE-2026-5883 Chrome Vulnerability: Critical Use-After-Free in Media Component Requires Immediate Patching
Google has released Chrome 147.0.7727.55 to address CVE-2026-5883, a critical use-after-free vulnerability in the browser's Media component. This security flaw affects all Chrome versions prior to...
CVE-2026-5885: Critical WebML Vulnerability in Chrome on Windows Exposes Memory Data
Microsoft has confirmed a critical security vulnerability in Chromium-based browsers on Windows systems that could allow attackers to access sensitive memory data. CVE-2026-5885, rated with a CVSS...