Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
A Low-Severity Chrome iOS Bug and the CPE Mix-Up That Almost Hid It
On June 30, 2026, the National Vulnerability Database published CVE-2026-14068, a vulnerability in Chrome for iOS’s Omnibox—the combined address and search bar. It was fixed before version...
Chrome 150 Closes WebXR Loophole That Could Hijack Your VR Browsing Session
Google shipped Chrome 150 to the stable channel on June 30, 2026, and tucked inside the update is a fix for a low-severity vulnerability that could let a malicious website escape a WebXR immersive...
Chrome 150.0.7871.47 Patches Low-Severity HTML Parsing Flaw That Could Enable Cross-Site Scripting
Google shipped Chrome 150.0.7871.47 to the stable channel for Windows and macOS on June 30, 2026, closing a low-severity universal cross-site scripting (UXSS) vulnerability now cataloged as...
Chrome 150 Patches CSS Side-Channel Flaw That Exposed Cross-Origin Data on Windows and Mac
Google shipped an urgent update for Chrome on Monday, closing a CSS-based side-channel vulnerability that could allow remote attackers to steal sensitive cross-origin data from embedded web pages....
Chrome 150 for Android Patches Sandbox Escape Bug—NVD Tags It 'Low' Severity
Google’s latest stable release of Chrome for Android, version 150, includes a patch for a sandbox escape vulnerability that the National Vulnerability Database (NVD) has classified as “Low”...
Chrome 150 Fixes CVE-2026-14107: Why You Should Update Now Despite Its Low Severity Rating
On June 30, 2026, Google shipped Chrome 150 to the stable channel for Windows, macOS, and Linux, addressing a use-after-free vulnerability in Chromium’s Scheduling component. Though labeled...
Chrome 150 Patch Closes PDFium Use-After-Free Bug—Update Now to Block Malicious PDF Attacks
Google rolled out an urgent security update for Chrome on June 30, 2026, patching a dangerous use-after-free flaw in the browser's PDF rendering engine that could let attackers hijack a computer...
Google Issues Fix for WebProtect Use-After-Free Flaw in Chrome 150
Google on June 30, 2026 disclosed a low-severity use-after-free vulnerability in Chrome’s WebProtect component, tracked as CVE-2026-14111. The bug, which required an attacker to persuade a user...
Critical Chrome Updater Bug CVE-2026-14113 Hits Windows: Patch to 150.0.7871.47 Now
Google has patched a high-severity security flaw in the Chrome browser’s updater for Windows that could allow an attacker who has already compromised a renderer process to break out of the...
Chrome 150 Patches Low-Severity Flaw That Could Leak Sensitive Data via DevTools
Google shipped Chrome 150.0.7871.47 to the stable channel on June 30, 2026, patching a low-severity vulnerability that could let a remote attacker steal cross-origin data if a user inspects a...
CVE-2026-14120: Chrome 150 Fixes DevTools Sandbox Escape
Google shipped Chrome 150 with a critical patch on June 30, 2026, closing a high-severity DevTools vulnerability that could allow attackers to escape the browser’s protective sandbox after...
Chrome for Android Fixes Autofill Spoofing Bug That Could Trick Users into Handing Over Passwords
Google has patched a low-severity flaw in Chrome for Android that allowed attackers to spoof the browser’s Autofill interface, potentially duping users into exposing saved credentials on malicious...