Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome 150 Fixes Low-Severity Bug That Could Complete a Sandbox Escape Chain
Google shipped Chrome 150 to the stable channel on June 30, 2026, closing a low-severity validation flaw that, on its own, seems minor—but could serve as a critical link in a sandbox-escape attack...
Chrome 150 Patch Closes macOS Sandbox Escape Hole (CVE-2026-14097)
Google shipped Chrome 150.0.7871.47 for macOS on June 30, 2026, containing a fix for a sandbox escape vulnerability tracked as CVE-2026-14097. The flaw, rooted in the browser’s WebAppInstalls...
Google Ships Emergency Chrome Update to Stop CSS-Based Data Theft
Google disclosed a high-severity flaw in Chrome on June 30, 2026, that made it possible for hackers to bypass the browser’s same-origin policy and read sensitive data from other websites using...
Google Patches Chrome NetworkCache Flaw That Could Leak Cross-Origin Browsing Data
On June 30, 2026, Google disclosed a security flaw in its Chrome browser that allowed malicious websites to potentially snatch data from other origins through the browser’s caching system. The...
Chrome 150.0.7871.47 Fixes Password Manager Use-After-Free Flaw — Update Now
On June 30, 2026, Google released Chrome version 150.0.7871.47 for Windows and Mac, patching a critical memory bug in the browser’s built-in password manager. The flaw, catalogued as...
NVD Clarifies Chrome Zero-Day CVE-2026-14103 Only Affects ChromeOS, Not Windows or Mac
The National Vulnerability Database has finally straightened out a glaring misconfiguration that had security teams scrambling over a critical use-after-free bug in Google Chrome. On July 2, 2026,...
Google Quietly Patches Chrome's WebAppInstalls as US Government Flags Critical 9.8 Severity—Update Now
Google shipped Chrome 150.0.7871.47 for Windows and Mac on June 30, 2026, to close a remote-code-execution hole in WebAppInstalls. The National Vulnerability Database assigned the flaw a critical 9.8...
Chrome 150.0.7871.47 Plugs Mojo Policy Bypass That Could Let Attackers Escape the Sandbox
Google rolled out Chrome 150.0.7871.47 on June 30, 2026, patching a Mojo policy-enforcement vulnerability that could let an attacker break out of the browser’s sandbox after first compromising a...
Chrome Dark Mode Flaw CVE-2026-14110 Lets Attackers Spoof Browser UI — Patch Now
Google released an urgent fix on June 30, 2026 for a high-severity vulnerability in Chrome that allows remote attackers to spoof the browser’s user interface through specifically crafted web pages....
Chrome 150’s Silent Patch Fixes an Enterprise Data Leak That IT Teams Shouldn’t Overlook
On June 30, Google pushed a stable channel update for Chrome on Windows and macOS that fixes a single vulnerability. The version, 150.0.7871.47, patches CVE-2026-14112—an information disclosure bug...
Chrome 150 Patches Critical Cast Flaw—Update Now to Avoid Windows Code Execution
Chrome 150.0.7871.47 landed on June 30, 2026, with a single but critical mission: plug a security hole in the browser’s Cast functionality that could let an attacker execute malware on a Windows PC...
Chrome 150 Patch Seals Windows-Only DevTools Memory Leak — Update Now
Google on June 30, 2026 patched a memory leak vulnerability in its Chrome browser for Windows, a bug that could let attackers crash the application by exploiting the developer tools. The fix, part of...