Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome’s ‘Low-Severity’ CVE-2026-14092 Privacy Bug Is Actually a Cross-Origin Data Leak—Update to 150.0.7871.47
Google released Chrome 150.0.7871.47 on June 30, 2026, to fix what it labeled a low-severity privacy flaw. But the National Vulnerability Database (NVD) and the U.S. Cybersecurity and Infrastructure...
Chrome Speech Flaw Spawns CVSS Score War—Why Windows Users Must Update Now
Google shipped a patch for a speech-recognition vulnerability in Chrome yesterday, but conflicting severity scores from two major authorities have muddied the waters for Windows users trying to gauge...
Chrome 150.0.7871.47 Closes CVE-2026-14116, a Low-Risk DevTools Security Bug
Google's June 30, 2026 stable channel update for Chrome, version 150.0.7871.47, includes a fix for a newly disclosed security vulnerability in the browser's developer tools. Tracked as...
Google Chrome 150 Fixes Omnibox Spoofing Flaw — Here’s Why You Should Update Now
Google released Chrome 150.0.7871.47 on June 30, 2026, patching a vulnerability that could let attackers spoof the browser’s Omnibox security UI. The low-severity bug, tracked as CVE-2026-14130,...
Google Chrome 150.0.7871.47 Fixes Extensions UI Spoofing Vulnerability – Update Your Browser
Google shipped Chrome 150.0.7871.47 this week, carrying a patch for a newly disclosed vulnerability in the browser's extensions framework. The flaw, cataloged as CVE-2026-14142, enables UI spoofing...
Chrome users must update now: Critical CVE‑2026‑13774 allows takeover via extensions
Google has released an emergency update for its Chrome browser to patch a critical use‑after‑free vulnerability, catalogued as CVE‑2026‑13774, that could let a malicious browser extension...
Chrome 150.0.7871.47 Patches PDF Input-Validation Flaw CVE-2026-13962 — Here’s What You Need to Do
On June 30, 2026, Google disclosed a medium-severity security vulnerability in Chrome’s built-in PDF viewer and immediately issued a fix in desktop version 150.0.7871.47. The flaw, tracked as...
Chrome Update 150.0.7871.47 Patches Password Spoofing Vulnerability (CVE-2026-13960)
Google has shipped a fix for a medium-severity security flaw in Chrome’s built-in password manager that could have allowed attackers to trick users into handing over their credentials. The...
CVE-2026-13959: Chrome's Same-Origin Policy Bypass Impacts All Versions Before 150.0.7871.47 – Update Immediately
Google published a fix for CVE-2026-13959 on June 30, 2026, patching a medium‑severity vulnerability in Chrome’s Blink engine that could let an attacker bypass the same‑origin policy. The flaw,...
Chrome Extension UI Flaw Gets Emergency CVE as CISA and NIST Rush Analysis
Google Chrome users have been put on alert after a critical vulnerability in the browser’s extension security interface received an official CVE identifier, triggering swift action from federal...
Chrome 150.0.7871.47 Closes Memory Leak That Could Expose Sensitive Data on Windows – Yet Scanner Glitches Linger
Google shipped a critical update for Chrome 150 on Windows on June 30, 2026, patching a vulnerability that could let attackers steal sensitive information from a computer’s memory using nothing...
Chrome 150.0.7871.47 Fixes a UI Spoof That Tricks Users Into Trusting Fake Sites
Google has shipped a fix for a high-severity interface spoofing bug in Chrome that could let an attacker pass off a malicious website as a trusted one, tricking users into handing over passwords or...