Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome 150 Patch Closes Codec Bug That Leaked Memory on Windows
Google patched a medium-severity information disclosure flaw in Chrome 150 for Windows on June 30, 2026. The vulnerability, tracked as CVE-2026-14010, allowed attackers to potentially read...
Chrome 150 Patches High-Severity Sandbox Escape: Update Now
Google on June 30, 2026, shipped Chrome version 150.0.7871.47 to fix a severe navigation implementation flaw that could let attackers break out of the browser's sandbox. Tracked as CVE-2026-14017,...
Chrome 150.0.7871.47 Fixes Medium-Severity StorageAccessAPI Cross-Origin Leak
On June 30, 2026, Google released a stable channel update for Chrome that includes a fix for CVE-2026-14021, a medium-severity vulnerability in the StorageAccessAPI. The flaw, which came to light...
Google Fixes Chrome SanitizerAPI Flaw That Allowed Attackers to Snoop Across Websites
Google released Chrome version 150.0.7871 with a fix for CVE-2026-14023, a vulnerability in the SanitizerAPI that an attacker could exploit to bypass same-origin restrictions. The company rated the...
Google Fixes Chrome Use-After-Free on macOS — Why the Same Update Matters for Windows
On June 30, 2026, Google pushed Chrome version 150.0.7871.47 to the stable desktop channel, patching a use-after-free vulnerability in the browser’s Views framework that specifically affects macOS....
Chrome Linux Hit by Omnibox Spoofing CVE-2026-14030—Patch Now to 150.0.7871.47
The National Vulnerability Database (NVD) on June 30, 2026, published a new Chrome vulnerability that lets a malicious website falsify the browser’s address bar on Linux systems. Tracked as...
Chrome 150 for Android patches WebXR navigation bypass with emergency update
Google has shipped Chrome 150.0.7871.47 for Android, closing a WebXR vulnerability that could let a remote attacker bypass navigation restrictions. The flaw, tracked as CVE-2026-14034, was disclosed...
Chrome 150 Fixes Extensions Flaw That Could Leak Your Private Data – Update Now
Google shipped an emergency update to Chrome’s stable desktop channel on June 30, 2026, patching a vulnerability in the browser’s extensions system that could allow attackers to steal sensitive...
Chrome 150.0.7871.47 Patches Navigation Bypass on Windows — Update Now to Block Remote Attacks
Google shipped an urgent but low-severity fix for Chrome on Windows and Mac on June 30, 2026. The update, version 150.0.7871.47, closes a single security hole—CVE-2026-14054—that let a remote...
Chrome’s FedCM Flaw Lets Attackers Skip Same-Origin Rules—Update to 150.0.7871.47 Now
On June 30, 2026, the National Vulnerability Database published CVE-2026-14057—a high-severity flaw in Google Chrome’s Federated Credential Management (FedCM) API that allows remote attackers to...
Google Ships Fix for Chrome Parser Flaw That Let Attackers Skirt Webpage Defenses
Google has patched a low‑severity vulnerability in Chrome’s HTML parser that could allow an attacker to bypass Content Security Policy (CSP) protections on any website. The fix, tracked as...
Google Patches Chrome for Windows After Chromoting Bug Grants Attackers Local Admin Rights
Google shipped an emergency fix for Chrome on Windows on June 30, 2026, closing a local privilege escalation flaw in Chromoting that could hand an attacker full control of a PC. The patch, delivered...