Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Google Fixes Chrome 150 Network Flaw That Opens Door to Script Injection on Windows
Google released a security update for Chrome on June 30, 2026, patching a vulnerability that could let attackers inject malicious scripts into any website open in the browser. The flaw, tracked as...
Google Chrome 150.0.7871.47 Fixes Geolocation UI Spoofing Vulnerability
Google shipped a patch on June 30, 2026 that closes a medium-severity flaw in Chrome’s geolocation implementation. Tracked as CVE-2026-14002, the bug could let an attacker who had already...
Google Pushes Chrome 150 Update to Block Extensions from Leaking Cross-Origin Data
Google shipped Chrome 150.0.7871.47 on June 30, 2026, closing a medium-severity vulnerability that could let a malicious browser extension swipe data from websites you visit—even if those sites are...
Chrome 150 Fixes Sneaky CSS Attack That Silently Stole Data Between Tabs
Google shipped an emergency patch in its latest Chrome 150 stable channel update to block a vulnerability that let malicious websites steal sensitive data from other origins simply by injecting...
Update Chrome for Android Now — WebXR Memory Leak Flaw CVE-2026-14008 Exposes Sensitive Data
Google shipped an urgent fix for Chrome on Android on June 30, 2026, closing a data-stealing hole in the browser’s WebXR component. The vulnerability, tracked as CVE-2026-14008, allows a remote...
Chrome 150 Emergency Update Fixes Password Manager Heap Corruption—Immediate Action Required
Google has pushed out Chrome 150 to the stable channel with a critical fix for a high-severity heap corruption vulnerability lurking in the browser’s built-in password manager. The flaw, tracked as...
Chrome 150 Out-of-Bounds Read Fix: Why a ‘Medium’ Severity Bug Still Demands Immediate Action
On June 30, 2026, Google shipped a stable channel update for Chrome 150 that patches CVE-2026-14011, an out-of-bounds read vulnerability in the browser’s SurfaceCapture component. The flaw is...
Chrome CSS side-channel attack leaks sensitive data on Windows: Patch released
Google disclosed a medium-severity security flaw in its Chrome browser on June 30, 2026, that could let attackers read sensitive information from your computer's memory just by tricking you into...
SVG Trick Could Let Attackers Spoof Chrome’s UI — Patch Now Arrives in Version 150
Google on June 30 pushed an emergency-ish update for Chrome that closes a hole attackers could exploit to trick you into thinking a fake dialog box, address bar, or other interface element is the...
Google Patches Chrome UI Spoofing Flaw That Could Trick Users Into Clicking Fake Buttons
Google shipped an emergency fix for a Chrome vulnerability on June 30, 2026, that attackers could use to spoof the browser’s interface—tricking users into clicking fake buttons, entering data...
Chrome 150 Patches WebRTC Race Condition Causing Cross-Origin Data Leaks on Windows
Google rolled out Chrome 150 on June 30, 2026, delivering a fix for CVE-2026-14015, a medium-severity race condition in WebRTC that could allow malicious websites to steal data across different...
Google Chrome's Updater Has a Critical Bug—Update Before Attackers Exploit It (CVE-2026-14018)
Google has rushed out a fix for a serious security flaw in the Chrome Updater on Windows that could allow an attacker who has already gained a foothold on your PC to seize full control of the system....