Chrome Vulnerability
The latest Chrome Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome 150.0.7871.47 Patches High‑Severity Extension UI Spoofing Flaw (CVE‑2026‑13999)
Google released Chrome 150.0.7871.47 to the Stable channel on June 30, 2026, fixing a potentially dangerous UI spoofing vulnerability in the browser's extension system. The flaw, tracked as...
Google Fixes Critical Chrome Installer Flaw That Gives Attackers Windows Admin Rights
Google shipped an emergency patch for Chrome on Windows late Tuesday, closing a dangerous security hole in the browser’s installer that could hand full system control to a local attacker. The fix,...
NVD’s CPE change muddles severity of Chrome’s Windows-only fix — what you should know
Google has shipped a patch for a Windows-only vulnerability in Chrome’s WebAppInstalls component, tracked as CVE-2026-14122, but the severity rating assigned by the U.S. National Vulnerability...
Chrome’s Latest Zero-Day Fix: Why You Need to Update Beyond 150.0.7871.47 Now
Google has shipped an emergency security update to Chrome’s stable channel, fixing a dangerous use-after-free vulnerability in the browser’s navigation system. The patch, tagged CVE-2026-14006,...
CVE-2026-13959: Chrome's Same-Origin Policy Bypass Impacts All Versions Before 150.0.7871.47 – Update Immediately
Google published a fix for CVE-2026-13959 on June 30, 2026, patching a medium‑severity vulnerability in Chrome’s Blink engine that could let an attacker bypass the same‑origin policy. The flaw,...
Google Chrome’s Password Manager Had a Cross-Origin Leak—Update Now to 150.0.7871.47
On June 30, 2026, Google disclosed a medium-severity vulnerability in Chrome’s built-in password manager that could allow a remote attacker to siphon saved credentials from other websites you’ve...
Chrome's Glic Flaw Lets Attackers Spoof UI Elements—Patch Now
Google disclosed a high-severity vulnerability in Chrome on June 30, 2026 that allows remote attackers to spoof the browser's user interface, potentially tricking users into revealing sensitive...
Chrome 149.0.7827.197 Fixes High-Severity GPU Memory Disclosure Flaw CVE-2026-13023
Google has rushed out an emergency update for Chrome, patching a high-severity vulnerability that could allow attackers to leak sensitive data from a computer's GPU memory. The flaw, tracked as...
Chrome’s Password Flaw Gets an NVD CVE—But CPE Chaos Could Muddy Windows Patch Efforts
The National Vulnerability Database assigned CVE-2026-11695 on June 8, 2026, a high-severity designation for a remote attack vector targeting Google Chrome’s password manager, weeks after the...
Google Chrome 149 Patches High-Severity Site Isolation Bypass Vulnerability (CVE-2026-11693)
Google pushed out Chrome 149.0.7827.103 on June 8, 2026, to stamp out a high-severity security hole that let attackers circumvent the browser's Site Isolation defenses after compromising a renderer...
Critical Chrome CVE-2026-11630 Flaw Hits Windows: Update to 149.0.7827.103 Now
Google has released Chrome 149.0.7827.103 for Windows, Mac, and Linux to address a critical security flaw that could allow attackers to hijack systems through a specially crafted web page. The...
Google Patches Critical Chrome Use-After-Free Bug Allowing Sandbox Escape on Windows
Google has sealed a critical vulnerability in Chrome that could have let attackers break out of the browser’s sandbox and run malicious code on Windows computers. The flaw, tracked as...