Serious Discussion Google Chrome Stable Channel Updates

Chrome & Chromium
500 Replies 146,049 Views
Google Chrome 150.0.7871.128/.129 Stable Channel Update for Desktop
This update includes 7 security fixes.

[N/A][516987782] Critical CVE-2026-15899: Use after free in CameraCapture. Reported by Google on 2026-05-27

[N/A][523750584] Critical CVE-2026-15900: Use after free in GPU. Reported by Google on 2026-06-14

[N/A][533446300] Critical CVE-2026-15901: Use after free in Network. Reported by Google on 2026-07-10

[N/A][522436154] High CVE-2026-15902: Use after free in Cast. Reported by Google on 2026-06-10

[TBD][531503216] High CVE-2026-15903: Out of bounds read and write in V8. Reported by OpenAI Codex Security (amyb) on 2026-07-06

[N/A][532925350] High CVE-2026-15904: Use after free in Ozone. Reported by Google on 2026-07-09

[N/A][532970574] High CVE-2026-15905: Use after free in Aura. Reported by Google on 2026-07-09
 
Google Chrome 150.0.7871.181/.182 Stable Channel Update for Desktop
This update includes 12 security fixes.

[$500][527930356] High CVE-2026-16420: Type Confusion in WebAudio. Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt on 2026-06-26

[$500][528276487] High CVE-2026-16421: Inappropriate implementation in WebAudio. Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt on 2026-06-26

[N/A][517359779] High CVE-2026-16413: Out of bounds write in ANGLE. Reported by Google on 2026-05-28

[N/A][517651910] High CVE-2026-16414: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-05-28

[N/A][519244446] High CVE-2026-16415: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-06-02

[N/A][520172356] High CVE-2026-16416: Integer overflow in Chromecast. Reported by Google on 2026-06-05

[N/A][521491024] High CVE-2026-16417: Uninitialized Use in Skia. Reported by Google on 2026-06-08

[N/A][522125255] High CVE-2026-16418: Stack buffer overflow in V8. Reported by Google on 2026-06-10

[N/A][523435970] High CVE-2026-16419: Out of bounds read and write in ANGLE. Reported by Google on 2026-06-13

[N/A][533515002] High CVE-2026-16422: Insufficient validation of untrusted input in Certificate. Reported by Google on 2026-07-10

[N/A][534582496] High CVE-2026-16423: Use after free in UI. Reported by Google on 2026-07-14

[N/A][534858939] High CVE-2026-16424: Use after free in GPU. Reported by Google on 2026-07-14
 
Google Chrome 150.0.7871.186/.187 Stable Channel Update for Desktop
This update includes 4 security fixes. Please see the Chrome Security Page for more information.

[N/A][518237034] High CVE-2026-16807: Out of bounds write in Codecs. Reported by Google on 2026-05-30

[N/A][522064153] High CVE-2026-16806: Use after free in WebMCP. Reported by Google on 2026-06-10

[N/A][523292588] High CVE-2026-16805: Use after free in Blink. Reported by Google on 2026-06-12

[N/A][524721670] High CVE-2026-16804: Use after free in Input. Reported by Google on 2026-06-16
 
Google Chrome 151.0.7922.71/.72 Stable Channel Update for Desktop
This update includes 370 security fixes. Please see the Chrome Security Page for more information.

[N/A][514442821] Critical CVE-2026-17650: Use after free in Compositing. Reported by Google on 2026-05-18

[N/A][517307966] Critical CVE-2026-17651: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-05-28

[N/A][519262990] Critical CVE-2026-17652: Use after free in Views. Reported by Google on 2026-06-02

[N/A][520514458] Critical CVE-2026-17653: Use after free in Skia. Reported by Google on 2026-06-05

[N/A][522314940] Critical CVE-2026-17654: Race in Updater. Reported by Google on 2026-06-10

[N/A][522556145] Critical CVE-2026-17655: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-06-11

[N/A][523725277] Critical CVE-2026-17656: Use after free in Ozone. Reported by Google on 2026-06-14

[$36000][502293787] High CVE-2026-17657: Use after free in Navigation. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-14

[$1000][523030583] High CVE-2026-17658: Use after free in V8. Reported by Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security on 2026-06-12

[N/A][495463654] High CVE-2026-17659: Inappropriate implementation in SiteIsolation. Reported by Google on 2026-03-23

[N/A][497428001] High CVE-2026-17660: Insufficient validation of untrusted input in Network. Reported by Google on 2026-03-29

[N/A][497451790] High CVE-2026-17661: Use after free in Loader. Reported by Google on 2026-03-29

[N/A][497491557] High CVE-2026-17662: Insufficient policy enforcement in Prefetch. Reported by Google on 2026-03-29

[N/A][500225310] High CVE-2026-17663: Insufficient validation of untrusted input in GPU. Reported by Google on 2026-04-07

[N/A][500554346] High CVE-2026-17664: Insufficient validation of untrusted input in Loader. Reported by Google on 2026-04-08

[N/A][511277457] High CVE-2026-17665: Use after free in V8. Reported by Google on 2026-05-08

[N/A][511761758] High CVE-2026-17666: Cryptographic Flaw in Enterprise. Reported by Google on 2026-05-10

[N/A][513043537] High CVE-2026-17667: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14

[N/A][513134019] High CVE-2026-17668: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14

[N/A][513142464] High CVE-2026-17669: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-14

[N/A][513228974] High CVE-2026-17670: Use after free in Views. Reported by Google on 2026-05-14

[N/A][513257423] High CVE-2026-17671: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-14

[N/A][513375270] High CVE-2026-17672: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-05-15

[N/A][513735177] High CVE-2026-17673: Integer overflow in QUIC. Reported by Google on 2026-05-16

[N/A][513791232] High CVE-2026-17674: Inappropriate implementation in HTML. Reported by Google on 2026-05-16

[N/A][513920258] High CVE-2026-17675: Out of bounds write in ANGLE. Reported by Google on 2026-05-17

[N/A][513920298] High CVE-2026-17676: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17

[N/A][513921488] High CVE-2026-17677: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17

[N/A][515452019] High CVE-2026-17678: Out of bounds read in ANGLE. Reported by Google on 2026-05-21

[N/A][516430649] High CVE-2026-17679: Insufficient validation of untrusted input in Print Preview. Reported by Google on 2026-05-25

[N/A][516486611] High CVE-2026-17680: Heap buffer overflow in Color. Reported by Google on 2026-05-25

[N/A][516813184] High CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication. Reported by Google on 2026-05-26

[N/A][516837126] High CVE-2026-17682: Integer overflow in ANGLE. Reported by Google on 2026-05-26

[N/A][516887576] High CVE-2026-17683: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-26

[N/A][516894682] High CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-26

[N/A][516910278] High CVE-2026-17685: Use after free in Autofill. Reported by Google on 2026-05-27

[N/A][516917065] High CVE-2026-17686: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-27

[N/A][516985726] High CVE-2026-17687: Type Confusion in ANGLE. Reported by Google on 2026-05-27

[N/A][517016413] High CVE-2026-17688: Use after free in Input. Reported by Google on 2026-05-27

[N/A][517045160] High CVE-2026-17689: Uninitialized Use in ANGLE. Reported by Google on 2026-05-27

[N/A][517129282] High CVE-2026-17690: Insufficient validation of untrusted input in PDF. Reported by Google on 2026-05-27

[N/A][517321292] High CVE-2026-17691: Out of bounds write in ANGLE. Reported by Google on 2026-05-28

[N/A][517350808] High CVE-2026-17692: Use after free in DataTransfer. Reported by Google on 2026-05-28

[N/A][517448723] High CVE-2026-17693: Inappropriate implementation in FileSystem. Reported by Google on 2026-05-28

[N/A][517511796] High CVE-2026-17694: Use after free in DOM. Reported by Google on 2026-05-28

[N/A][517543052] High CVE-2026-17695: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-28

[N/A][517550034] High CVE-2026-17696: Side-channel information leakage in Media. Reported by Google on 2026-05-28

[N/A][517575864] High CVE-2026-17697: Type Confusion in ANGLE. Reported by Google on 2026-05-28

[N/A][517670731] High CVE-2026-17698: Insufficient validation of untrusted input in UI. Reported by Google on 2026-05-29

[N/A][517785292] High CVE-2026-17699: Use after free in Views. Reported by Google on 2026-05-29

[N/A][517789833] High CVE-2026-17700: Insufficient validation of untrusted input in Actor. Reported by Google on 2026-05-29

[N/A][517972648] High CVE-2026-17701: Out of bounds read in ANGLE. Reported by Google on 2026-05-29

[N/A][517973093] High CVE-2026-17702: Inappropriate implementation in Skia. Reported by Google on 2026-05-29

[N/A][518051499] High CVE-2026-17703: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][519259107] High CVE-2026-17704: Use after free in ANGLE. Reported by Google on 2026-06-02

[TBD][519665978] High CVE-2026-17705: Integer overflow in libxml. Reported by ebassi of Igalia on 2026-06-04

[N/A][519693032] High CVE-2026-17706: Insufficient validation of untrusted input in Media. Reported by Google on 2026-06-03

[N/A][519701233] High CVE-2026-17707: Uninitialized Use in Media. Reported by Google on 2026-06-03

[N/A][519738647] High CVE-2026-17708: Use after free in Audio. Reported by Google on 2026-06-04

[N/A][519981494] High CVE-2026-17709: Race in Downloads. Reported by Google on 2026-06-04

[N/A][519991712] High CVE-2026-17710: Inappropriate implementation in MHTML. Reported by Google on 2026-06-04

[N/A][519996040] High CVE-2026-17711: Race in Downloads. Reported by Google on 2026-06-04

[N/A][520535595] High CVE-2026-17712: Race in Skia. Reported by Google on 2026-06-05

[N/A][520572766] High CVE-2026-17713: Insufficient validation of untrusted input in Accessibility. Reported by Google on 2026-06-06

[N/A][521293438] High CVE-2026-17714: Uninitialized Use in ANGLE. Reported by Google on 2026-06-08

[N/A][521491778] High CVE-2026-17715: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08

[N/A][521866061] High CVE-2026-17716: Use after free in Updater. Reported by Google on 2026-06-09

[N/A][522063116] High CVE-2026-17717: Integer overflow in ANGLE. Reported by Google on 2026-06-10

[N/A][522079372] High CVE-2026-17718: Use after free in ANGLE. Reported by Google on 2026-06-10

[N/A][522304853] High CVE-2026-17719: Use after free in Input. Reported by Google on 2026-06-10

[N/A][522545249] High CVE-2026-17720: Insufficient policy enforcement in Passwords. Reported by Google on 2026-06-11

[N/A][523495723] High CVE-2026-17721: Out of bounds write in ANGLE. Reported by Google on 2026-06-13

[N/A][523592755] High CVE-2026-17722: Object lifecycle issue in WebView. Reported by Google on 2026-06-13

[N/A][523718303] High CVE-2026-17723: Use after free in Media. Reported by Google on 2026-06-14

[N/A][523720739] High CVE-2026-17724: Race in Chrome for iOS. Reported by Google on 2026-06-14

[TBD][528501127] High CVE-2026-17725: Type Confusion in V8. Reported by nh.dev2022 on 2026-06-27

[N/A][529867799] High CVE-2026-17726: Integer overflow in WebGL. Reported by Google on 2026-06-30

[N/A][529932631] High CVE-2026-17727: Out of bounds write in WebGL. Reported by Google on 2026-07-01

[$10000][461167648] Medium CVE-2026-17728: Inappropriate implementation in Extensions. Reported by Suhas S P on 2025-11-16

[$5000][503801946] Medium CVE-2026-17758: Heap buffer overflow in Dawn. Reported by Hyeonjun Ahn (@_deayzl) on 2026-04-18

[$2000][476646486] Medium CVE-2026-17732: Inappropriate implementation in SVG. Reported by Lyra Rebane (rebane2001) on 2026-01-17

[$500][520656237] Medium CVE-2026-17729: Use after free in V8. Reported by wang1r && lhfff on 2026-06-07

[N/A][40057032] Medium CVE-2026-17730: Side-channel information leakage in Autofill. Reported by Google on 2021-08-26

[TBD][463551850] Medium CVE-2026-17731: Inappropriate implementation in Autofill. Reported by Manojkumar Jaganathan Aka TheWhiteEvil with HackerBro Technologies on 2025-11-25

[N/A][495793059] Medium CVE-2026-17733: Inappropriate implementation in QUIC. Reported by Google on 2026-03-24

[N/A][496304083] Medium CVE-2026-17734: Inappropriate implementation in Autofill. Reported by Google on 2026-03-25

[N/A][496569497] Medium CVE-2026-17735: Insufficient validation of untrusted input in BFCache. Reported by Google on 2026-03-26

[N/A][496715442] Medium CVE-2026-17736: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-03-27

[N/A][498000415] Medium CVE-2026-17737: Use after free in Bluetooth. Reported by Google on 2026-03-31

[N/A][498079379] Medium CVE-2026-17738: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-03-31

[N/A][498353463] Medium CVE-2026-17739: Insufficient policy enforcement in Extensions. Reported by Google on 2026-03-31

[N/A][498827800] Medium CVE-2026-17740: Uninitialized Use in ANGLE. Reported by Google on 2026-04-02

[N/A][498877660] Medium CVE-2026-17741: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-04-02

[N/A][499003233] Medium CVE-2026-17742: Insufficient policy enforcement in Payments. Reported by Google on 2026-04-02

[N/A][499204022] Medium CVE-2026-17743: Insufficient policy enforcement in ControlledFrame. Reported by Google on 2026-04-03

[N/A][500137309] Medium CVE-2026-17744: Inappropriate implementation in File Input. Reported by Google on 2026-04-07

[N/A][500172224] Medium CVE-2026-17745: Out of bounds read in Skia. Reported by Google on 2026-04-07

[N/A][500390256] Medium CVE-2026-17746: Use after free in GPU. Reported by Google on 2026-04-07

[N/A][500472958] Medium CVE-2026-17747: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-04-07

[N/A][500494349] Medium CVE-2026-17748: Inappropriate implementation in Extensions. Reported by Google on 2026-04-08

[N/A][500526602] Medium CVE-2026-17749: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-04-08

[N/A][500560234] Medium CVE-2026-17750: Use after free in ANGLE. Reported by Google on 2026-04-08

[N/A][501591293] Medium CVE-2026-17751: Inappropriate implementation in AdFilter. Reported by Google on 2026-04-11

[N/A][501619207] Medium CVE-2026-17752: Use after free in Views. Reported by Google on 2026-04-11

[N/A][501628355] Medium CVE-2026-17753: Inappropriate implementation in Autofill. Reported by Google on 2026-04-11

[N/A][501675996] Medium CVE-2026-17754: Inappropriate implementation in Blink. Reported by Google on 2026-04-11

[N/A][501854535] Medium CVE-2026-17755: Incorrect security UI in Extensions. Reported by Google on 2026-04-12

[N/A][501980797] Medium CVE-2026-17756: Insufficient policy enforcement in Presentation. Reported by Google on 2026-04-13

[N/A][502351526] Medium CVE-2026-17757: Uninitialized Use in Skia. Reported by Google on 2026-04-14

[N/A][504650654] Medium CVE-2026-17759: Uninitialized Use in Codecs. Reported by Google on 2026-04-20

[N/A][506473189] Medium CVE-2026-17760: Side-channel information leakage in NoStatePrefetch. Reported by Google on 2026-04-25

[N/A][508249524] Medium CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][508251844] Medium CVE-2026-17762: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][511738693] Medium CVE-2026-17763: Inappropriate implementation in GPU. Reported by Google on 2026-05-10

[N/A][511754400] Medium CVE-2026-17764: Inappropriate implementation in FedCM. Reported by Google on 2026-05-10

[N/A][511765328] Medium CVE-2026-17765: Inappropriate implementation in WebProtect. Reported by Google on 2026-05-10

[N/A][511799537] Medium CVE-2026-17766: Insufficient validation of untrusted input in Clipboard. Reported by Google on 2026-05-10

[N/A][511822402] Medium CVE-2026-17767: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-05-10

[N/A][512999037] Medium CVE-2026-17768: Insufficient validation of untrusted input in WebSockets. Reported by Google on 2026-05-13

[N/A][513022076] Medium CVE-2026-17769: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14

[N/A][513103345] Medium CVE-2026-17770: Out of bounds read in Media. Reported by Google on 2026-05-14

[N/A][513160525] Medium CVE-2026-17771: Uninitialized Use in Skia. Reported by Google on 2026-05-14

[N/A][513197846] Medium CVE-2026-17772: Out of bounds read in WebGL. Reported by Google on 2026-05-14

[N/A][513232523] Medium CVE-2026-17773: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14

[N/A][513323066] Medium CVE-2026-17774: Insufficient validation of untrusted input in Variations. Reported by Google on 2026-05-14

[N/A][513363822] Medium CVE-2026-17775: Inappropriate implementation in PresentationAPI. Reported by Google on 2026-05-15

[N/A][513404032] Medium CVE-2026-17776: Policy bypass in Receiver. Reported by Google on 2026-05-15

[N/A][513462236] Medium CVE-2026-17777: Inappropriate implementation in Autofill. Reported by Google on 2026-05-15

[N/A][513467993] Medium CVE-2026-17778: Use after free in Extensions. Reported by Google on 2026-05-15

[N/A][513478933] Medium CVE-2026-17779: Inappropriate implementation in Site Isolation. Reported by Google on 2026-05-15

[N/A][513485951] Medium CVE-2026-17780: Inappropriate implementation in Isolated Web Apps. Reported by Google on 2026-05-15

[N/A][513502990] Medium CVE-2026-17781: Inappropriate implementation in Extensions. Reported by Google on 2026-05-15

[N/A][513507830] Medium CVE-2026-17782: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-15

[N/A][513532735] Medium CVE-2026-17783: Inappropriate implementation in Loader. Reported by Google on 2026-05-15

[N/A][513694032] Medium CVE-2026-17784: Use after free in Audio. Reported by Google on 2026-05-16

[N/A][513769898] Medium CVE-2026-17785: Uninitialized Use in ANGLE. Reported by Google on 2026-05-16

[N/A][513770449] Medium CVE-2026-17786: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513783632] Medium CVE-2026-17787: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513824957] Medium CVE-2026-17788: Inappropriate implementation in Blink. Reported by Google on 2026-05-16

[N/A][513855922] Medium CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-16

[N/A][513919931] Medium CVE-2026-17790: Uninitialized Use in ANGLE. Reported by Google on 2026-05-17

[N/A][514006959] Medium CVE-2026-17791: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-17

[N/A][514019823] Medium CVE-2026-17792: Inappropriate implementation in Credential Management. Reported by Google on 2026-05-17

[N/A][514063859] Medium CVE-2026-17793: Inappropriate implementation in Messages. Reported by Google on 2026-05-17

[N/A][514067070] Medium CVE-2026-17794: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-05-17

[TBD][514242889] Medium CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia. Reported by Mihnea Nicolau on 2026-05-18

[N/A][514427844] Medium CVE-2026-17796: Side-channel information leakage in WebXR. Reported by Google on 2026-05-18

[N/A][514441966] Medium CVE-2026-17797: Inappropriate implementation in CSS. Reported by Google on 2026-05-18

[N/A][514460133] Medium CVE-2026-17798: Inappropriate implementation in Cast. Reported by Google on 2026-05-19

[N/A][514461031] Medium CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing. Reported by Google on 2026-05-19

[N/A][514480948] Medium CVE-2026-17800: Side-channel information leakage in MediaRecording. Reported by Google on 2026-05-19

[N/A][514482938] Medium CVE-2026-17801: Out of bounds memory access in ANGLE. Reported by Google on 2026-05-19

[N/A][514512198] Medium CVE-2026-17802: Side-channel information leakage in GPU. Reported by Google on 2026-05-19

[N/A][515438919] Medium CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive. Reported by Google on 2026-05-21

[N/A][515448947] Medium CVE-2026-17804: Use after free in Media. Reported by Google on 2026-05-21

[N/A][516420806] Medium CVE-2026-17805: Insufficient policy enforcement in Glic. Reported by Google on 2026-05-25

[N/A][516433058] Medium CVE-2026-17806: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-25

[N/A][516763884] Medium CVE-2026-17807: Use after free in V8. Reported by Google on 2026-05-26

[N/A][516778390] Medium CVE-2026-17808: Uninitialized Use in WebGL. Reported by Google on 2026-05-26

[N/A][516813317] Medium CVE-2026-17809: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-26

[N/A][516882109] Medium CVE-2026-17810: Uninitialized Use in Dawn. Reported by Google on 2026-05-26

[N/A][516954622] Medium CVE-2026-17811: Use after free in ANGLE. Reported by Google on 2026-05-27

[N/A][517101596] Medium CVE-2026-17812: Inappropriate implementation in DigitalCredentials. Reported by Google on 2026-05-27

[N/A][517184957] Medium CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-05-27

[N/A][517312048] Medium CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517427352] Medium CVE-2026-17815: Insufficient policy enforcement in GuestView. Reported by Google on 2026-05-28

[N/A][517429672] Medium CVE-2026-17816: Inappropriate implementation in Speech. Reported by Google on 2026-05-28

[N/A][517461759] Medium CVE-2026-17817: Inappropriate implementation in ReportingAndNEL. Reported by Google on 2026-05-28

[N/A][517466133] Medium CVE-2026-17818: Inappropriate implementation in Network. Reported by Google on 2026-05-28

[N/A][517487028] Medium CVE-2026-17819: Inappropriate implementation in WebAppInstalls. Reported by Google on 2026-05-28

[N/A][517493101] Medium CVE-2026-17820: Insufficient policy enforcement in Autofill. Reported by Google on 2026-05-28

[N/A][517597914] Medium CVE-2026-17821: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-28

[N/A][517621178] Medium CVE-2026-17822: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517628043] Medium CVE-2026-17823: Insufficient policy enforcement in WebXR. Reported by Google on 2026-05-28

[N/A][517655543] Medium CVE-2026-17824: Insufficient policy enforcement in ServiceWorker. Reported by Google on 2026-05-28

[N/A][517675979] Medium CVE-2026-17825: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29

[N/A][517690521] Medium CVE-2026-17826: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[N/A][517693726] Medium CVE-2026-17827: Inappropriate implementation in CSS. Reported by Google on 2026-05-29

[N/A][517702279] Medium CVE-2026-17828: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[N/A][517705103] Medium CVE-2026-17829: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29

[N/A][517710397] Medium CVE-2026-17830: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[N/A][517714728] Medium CVE-2026-17831: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-29

[N/A][517723319] Medium CVE-2026-17832: Use after free in ANGLE. Reported by Google on 2026-05-29

[N/A][517779123] Medium CVE-2026-17833: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29

[N/A][517793801] Medium CVE-2026-17834: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29

[N/A][517801739] Medium CVE-2026-17835: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[TBD][517972812] Medium CVE-2026-17836: Use after free in V8. Reported by yupyon.itome on 2026-05-30

[N/A][517978932] Medium CVE-2026-17837: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-29

[N/A][518075952] Medium CVE-2026-17838: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518080978] Medium CVE-2026-17839: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518082162] Medium CVE-2026-17840: Incorrect security UI in Passwords. Reported by Google on 2026-05-30

[N/A][518088219] Medium CVE-2026-17841: Race in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518089997] Medium CVE-2026-17842: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518103887] Medium CVE-2026-17843: Inappropriate implementation in CSS. Reported by Google on 2026-05-30

[N/A][518111542] Medium CVE-2026-17844: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-30

[N/A][518112775] Medium CVE-2026-17845: Inappropriate implementation in CSS. Reported by Google on 2026-05-30

[N/A][518121320] Medium CVE-2026-17846: Inappropriate implementation in Media. Reported by Google on 2026-05-30

[N/A][518243653] Medium CVE-2026-17847: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-30

[TBD][518284253] Medium CVE-2026-17848: Insufficient validation of untrusted input in Codecs. Reported by Ameen Basha M K on 2026-05-31

[N/A][518812672] Medium CVE-2026-17849: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-01

[TBD][519078527] Medium CVE-2026-17850: Inappropriate implementation in Permissions. Reported by Tech Division (@taiphung) - Mobifone Digital Payment on 2026-06-02

[N/A][519243927] Medium CVE-2026-17851: Side-channel information leakage in Autofill. Reported by Google on 2026-06-02

[N/A][519348818] Medium CVE-2026-17852: Inappropriate implementation in Media Router. Reported by Google on 2026-06-03

[TBD][519472272] Medium CVE-2026-17853: Inappropriate implementation in DevTools. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-06-03

[N/A][519500882] Medium CVE-2026-17854: Insufficient policy enforcement in WebMCP. Reported by Google on 2026-06-03

[N/A][519982572] Medium CVE-2026-17855: Race in DevTools. Reported by Google on 2026-06-04

[N/A][519991751] Medium CVE-2026-17856: Inappropriate implementation in Network. Reported by Google on 2026-06-04

[N/A][520186620] Medium CVE-2026-17857: Inappropriate implementation in Network. Reported by Google on 2026-06-05

[N/A][520191468] Medium CVE-2026-17858: Uninitialized Use in WebNN. Reported by Google on 2026-06-05

[N/A][520196753] Medium CVE-2026-17859: Side-channel information leakage in Favicons. Reported by Google on 2026-06-05

[N/A][520407381] Medium CVE-2026-17860: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-06-05

[N/A][520417861] Medium CVE-2026-17861: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-05

[N/A][520426287] Medium CVE-2026-17862: Use after free in Tracing. Reported by Google on 2026-06-05

[N/A][520468718] Medium CVE-2026-17863: Inappropriate implementation in Browser. Reported by Google on 2026-06-05

[N/A][520494861] Medium CVE-2026-17864: Inappropriate implementation in Updater. Reported by Google on 2026-06-05

[N/A][520516655] Medium CVE-2026-17865: Inappropriate implementation in Crypto. Reported by Google on 2026-06-05

[N/A][520525732] Medium CVE-2026-17866: Type Confusion in Tab. Reported by Google on 2026-06-05

[N/A][520527496] Medium CVE-2026-17867: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-06-05

[TBD][520743499] Medium CVE-2026-17868: Insufficient policy enforcement in USB. Reported by Ariel Simon on 2026-06-06

[N/A][521759269] Medium CVE-2026-17869: Out of bounds read in WebXR. Reported by Google on 2026-06-09

[N/A][521784856] Medium CVE-2026-17870: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-09

[N/A][521938924] Medium CVE-2026-17871: Inappropriate implementation in Passwords. Reported by Google on 2026-06-09

[N/A][521963740] Medium CVE-2026-17872: Cryptographic Flaw in WebAppInstalls. Reported by Google on 2026-06-09

[N/A][522074033] Medium CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-10

[N/A][522074154] Medium CVE-2026-17874: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-10

[N/A][522299155] Medium CVE-2026-17875: Use after free in PDFium. Reported by Google on 2026-06-10

[N/A][522425471] Medium CVE-2026-17876: Inappropriate implementation in Payments. Reported by Google on 2026-06-10

[N/A][522426086] Medium CVE-2026-17877: Inappropriate implementation in Chromoting. Reported by Google on 2026-06-10

[N/A][522781838] Medium CVE-2026-17878: Inappropriate implementation in CSS. Reported by Google on 2026-06-11

[N/A][522878450] Medium CVE-2026-17879: Inappropriate implementation in Autofill. Reported by Google on 2026-06-11

[N/A][523229759] Medium CVE-2026-17880: Inappropriate implementation in Autofill. Reported by Google on 2026-06-12

[N/A][523477987] Medium CVE-2026-17881: Use after free in WebXR. Reported by Google on 2026-06-13

[N/A][523637452] Medium CVE-2026-17882: Policy bypass in Extensions. Reported by Google on 2026-06-13

[N/A][523639090] Medium CVE-2026-17883: Inappropriate implementation in Headless. Reported by Google on 2026-06-13

[N/A][523692228] Medium CVE-2026-17884: Object lifecycle issue in WebRTC. Reported by Google on 2026-06-13

[N/A][523698038] Medium CVE-2026-17885: Inappropriate implementation in Paint. Reported by Google on 2026-06-13

[N/A][523715964] Medium CVE-2026-17886: Use after free in Enterprise. Reported by Google on 2026-06-14

[N/A][523717010] Medium CVE-2026-17887: Use after free in TabStrip. Reported by Google on 2026-06-14

[N/A][523720529] Medium CVE-2026-17888: Insufficient validation of untrusted input in WebUI. Reported by Google on 2026-06-14

[N/A][523735357] Medium CVE-2026-17889: Uninitialized Use in WebXR. Reported by Google on 2026-06-14

[N/A][524029061] Medium CVE-2026-17890: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-15

[N/A][524639223] Medium CVE-2026-17891: Use after free in ANGLE. Reported by Google on 2026-06-16

[N/A][524822998] Medium CVE-2026-17892: Inappropriate implementation in WebXR. Reported by Google on 2026-06-17

[N/A][524824730] Medium CVE-2026-17893: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-17

[N/A][524825209] Medium CVE-2026-17894: Use after free in Views. Reported by Google on 2026-06-17

[TBD][524931675] Medium CVE-2026-17895: Inappropriate implementation in DataTransfer. Reported by hongan@calif.io on 2026-06-17

[N/A][525331547] Medium CVE-2026-17896: Use after free in DevTools. Reported by Google on 2026-06-18

[TBD][527665262] Medium CVE-2026-17897: Inappropriate implementation in ORB. Reported by Sharkkcode on 2026-06-25

[$3000][506193577] Low CVE-2026-17898: Use after free in DevTools. Reported by Syn4pse on 2026-04-24

[$1000][375959766] Low CVE-2026-17899: Insufficient policy enforcement in DevTools. Reported by asnine on 2024-10-28

[N/A][496195854] Low CVE-2026-17900: Inappropriate implementation in Enterprise. Reported by Google on 2026-03-25

[N/A][496271098] Low CVE-2026-17901: Inappropriate implementation in Sharing. Reported by Google on 2026-03-25

[N/A][497251066] Low CVE-2026-17902: Inappropriate implementation in Editing. Reported by Google on 2026-03-28

[N/A][497277880] Low CVE-2026-17903: Insufficient policy enforcement in Chromecast. Reported by Google on 2026-03-28

[N/A][497337759] Low CVE-2026-17904: Insufficient policy enforcement in NFC. Reported by Google on 2026-03-29

[N/A][497366217] Low CVE-2026-17905: Inappropriate implementation in SurfaceCapture. Reported by Google on 2026-03-29

[N/A][497654761] Low CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth. Reported by Google on 2026-03-30

[N/A][497837927] Low CVE-2026-17907: Side-channel information leakage in Network. Reported by Google on 2026-03-30

[N/A][499062890] Low CVE-2026-17908: Insufficient validation of untrusted input in Printing. Reported by Google on 2026-04-02

[N/A][501693236] Low CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps. Reported by Google on 2026-04-11

[N/A][501749600] Low CVE-2026-17910: Insufficient policy enforcement in NFC. Reported by Google on 2026-04-11

[N/A][502505715] Low CVE-2026-17911: Insufficient policy enforcement in SVG. Reported by Google on 2026-04-14

[N/A][504202939] Low CVE-2026-17912: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19

[N/A][504209246] Low CVE-2026-17913: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19

[N/A][506377118] Low CVE-2026-17914: Side-channel information leakage in Skia. Reported by Google on 2026-04-25

[N/A][506390325] Low CVE-2026-17915: Inappropriate implementation in WebView. Reported by Google on 2026-04-25

[TBD][510808598] Low CVE-2026-17916: Insufficient policy enforcement in Settings. Reported by Itzik Chimino on 2026-05-07

[N/A][511816897] Low CVE-2026-17917: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-10

[N/A][513127137] Low CVE-2026-17918: Use after free in Sync. Reported by Google on 2026-05-14

[N/A][513291747] Low CVE-2026-17919: Insufficient policy enforcement in Enterprise. Reported by Google on 2026-05-14

[N/A][513413942] Low CVE-2026-17920: Use after free in V8. Reported by Google on 2026-05-15

[N/A][513503197] Low CVE-2026-17921: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-05-15

[N/A][513611659] Low CVE-2026-17922: Inappropriate implementation in Enterprise. Reported by Google on 2026-05-15

[N/A][513612928] Low CVE-2026-17923: Policy bypass in Enterprise. Reported by Google on 2026-05-15

[N/A][513714124] Low CVE-2026-17924: Use after free in DNS. Reported by Google on 2026-05-16

[N/A][513719671] Low CVE-2026-17925: Inappropriate implementation in Cast. Reported by Google on 2026-05-16

[N/A][513735900] Low CVE-2026-17926: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513754837] Low CVE-2026-17927: Insufficient policy enforcement in DevTools. Reported by Google on 2026-05-16

[N/A][513762372] Low CVE-2026-17928: Inappropriate implementation in DataTransfer. Reported by Google on 2026-05-16

[N/A][513768645] Low CVE-2026-17929: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513769158] Low CVE-2026-17930: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-16

[N/A][513781245] Low CVE-2026-17931: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513819157] Low CVE-2026-17932: Use after free in DataTransfer. Reported by Google on 2026-05-16

[N/A][513822044] Low CVE-2026-17933: Inappropriate implementation in DOMStorage. Reported by Google on 2026-05-16

[N/A][513838421] Low CVE-2026-17934: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513863267] Low CVE-2026-17935: Heap buffer overflow in Codecs. Reported by Google on 2026-05-16

[N/A][513864014] Low CVE-2026-17936: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513866380] Low CVE-2026-17937: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513989304] Low CVE-2026-17938: Inappropriate implementation in FullScreen. Reported by Google on 2026-05-17

[N/A][514060089] Low CVE-2026-17939: Inappropriate implementation in Passwords. Reported by Google on 2026-05-17

[N/A][514069440] Low CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture. Reported by Google on 2026-05-17

[N/A][514147906] Low CVE-2026-17941: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-18

[N/A][514406198] Low CVE-2026-17942: Side-channel information leakage in SVG. Reported by Google on 2026-05-18

[N/A][514424283] Low CVE-2026-17943: Inappropriate implementation in Parser. Reported by Google on 2026-05-18

[N/A][514510853] Low CVE-2026-17944: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-19

[N/A][514519203] Low CVE-2026-17945: Inappropriate implementation in Navigation. Reported by Google on 2026-05-19

[N/A][515437522] Low CVE-2026-17946: Uninitialized Use in Dawn. Reported by Google on 2026-05-21

[N/A][515438256] Low CVE-2026-17947: Use after free in WebSockets. Reported by Google on 2026-05-21

[N/A][516849257] Low CVE-2026-17948: Type Confusion in V8. Reported by Google on 2026-05-26

[N/A][517000034] Low CVE-2026-17949: Uninitialized Use in GPU. Reported by Google on 2026-05-27

[N/A][517063658] Low CVE-2026-17950: Policy bypass in Safebrowsing. Reported by Google on 2026-05-27

[N/A][517180511] Low CVE-2026-17951: Heap buffer overflow in WebRTC. Reported by Google on 2026-05-27

[N/A][517316174] Low CVE-2026-17952: Inappropriate implementation in V8. Reported by Google on 2026-05-28

[N/A][517335150] Low CVE-2026-17953: Insufficient policy enforcement in WebView. Reported by Google on 2026-05-28

[N/A][517383492] Low CVE-2026-17954: Policy bypass in MHTML. Reported by Google on 2026-05-28

[N/A][517385072] Low CVE-2026-17955: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-28

[N/A][517436171] Low CVE-2026-17956: Inappropriate implementation in Scheduling. Reported by Google on 2026-05-28

[N/A][517476342] Low CVE-2026-17957: Inappropriate implementation in CORS. Reported by Google on 2026-05-28

[N/A][517538206] Low CVE-2026-17958: Inappropriate implementation in Views. Reported by Google on 2026-05-28

[N/A][517607890] Low CVE-2026-17959: Inappropriate implementation in Network. Reported by Google on 2026-05-28

[N/A][517631680] Low CVE-2026-17960: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517700791] Low CVE-2026-17961: Inappropriate implementation in Session. Reported by Google on 2026-05-29

[N/A][517757268] Low CVE-2026-17962: Inappropriate implementation in Blink. Reported by Google on 2026-05-29

[N/A][517759257] Low CVE-2026-17963: Inappropriate implementation in SVG. Reported by Google on 2026-05-29

[N/A][518025103] Low CVE-2026-17964: Incorrect security UI in UI. Reported by Google on 2026-05-29

[N/A][518049812] Low CVE-2026-17965: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518058990] Low CVE-2026-17966: Inappropriate implementation in Views. Reported by Google on 2026-05-30

[N/A][518243858] Low CVE-2026-17967: Use after free in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518337516] Low CVE-2026-17968: Uninitialized Use in WebXR. Reported by Google on 2026-05-31

[N/A][518812295] Low CVE-2026-17969: Inappropriate implementation in Passwords. Reported by Google on 2026-06-01

[N/A][518814464] Low CVE-2026-17970: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-01

[N/A][518815075] Low CVE-2026-17971: Inappropriate implementation in Frame. Reported by Google on 2026-06-01

[N/A][519202895] Low CVE-2026-17972: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-02

[N/A][519230894] Low CVE-2026-17973: Inappropriate implementation in Views. Reported by Google on 2026-06-02

[N/A][519232592] Low CVE-2026-17974: Insufficient policy enforcement in DevTools. Reported by Google on 2026-06-02

[N/A][519233776] Low CVE-2026-17975: Inappropriate implementation in IME. Reported by Google on 2026-06-02

[N/A][519455164] Low CVE-2026-17976: Policy bypass in Extensions. Reported by Google on 2026-06-03

[N/A][519603552] Low CVE-2026-17977: Policy bypass in CSS. Reported by Google on 2026-06-03

[N/A][519610845] Low CVE-2026-17978: Side-channel information leakage in WebCodecs. Reported by Google on 2026-06-03

[N/A][519664497] Low CVE-2026-17979: Race in V8. Reported by Google on 2026-06-04

[N/A][519710361] Low CVE-2026-17980: Inappropriate implementation in UI. Reported by Google on 2026-06-03

[N/A][519719512] Low CVE-2026-17981: Inappropriate implementation in Blink. Reported by Google on 2026-06-03

[N/A][519735808] Low CVE-2026-17982: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-04

[N/A][519744561] Low CVE-2026-17983: Incorrect security UI in Global Media Controls. Reported by Google on 2026-06-04

[N/A][519978460] Low CVE-2026-17984: Inappropriate implementation in Browser. Reported by Google on 2026-06-04

[N/A][519981430] Low CVE-2026-17985: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-04

[N/A][519981896] Low CVE-2026-17986: Insufficient policy enforcement in Bluetooth. Reported by Google on 2026-06-04

[N/A][519988071] Low CVE-2026-17987: Insufficient validation of untrusted input in Notifications. Reported by Google on 2026-06-04

[N/A][520005624] Low CVE-2026-17988: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-06-04

[N/A][520017306] Low CVE-2026-17989: Type Confusion in V8. Reported by Google on 2026-06-04

[N/A][520018012] Low CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn. Reported by Google on 2026-06-04

[N/A][520110535] Low CVE-2026-17991: Insufficient validation of untrusted input in AI. Reported by Google on 2026-06-04

[N/A][520506316] Low CVE-2026-17992: Uninitialized Use in Skia. Reported by Google on 2026-06-05

[N/A][520532191] Low CVE-2026-17993: Race in Updater. Reported by Google on 2026-06-05

[N/A][520663771] Low CVE-2026-17994: Inappropriate implementation in Media. Reported by Google on 2026-06-06

[TBD][520972775] Low CVE-2026-17995: Out of bounds read in Dawn. Reported by sm1ee, ksw9722 on 2026-06-07

[N/A][521473427] Low CVE-2026-17996: Inappropriate implementation in Browser. Reported by Google on 2026-06-08

[N/A][521476960] Low CVE-2026-17997: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08

[N/A][521601450] Low CVE-2026-17998: Incorrect security UI in Extensions. Reported by Google on 2026-06-09

[N/A][521615681] Low CVE-2026-17999: Incorrect security UI in PictureInPicture. Reported by Google on 2026-06-09

[N/A][521623907] Low CVE-2026-18000: Insufficient policy enforcement in USB. Reported by Google on 2026-06-09

[N/A][521757779] Low CVE-2026-18001: Inappropriate implementation in WebGL. Reported by Google on 2026-06-09

[N/A][521864362] Low CVE-2026-18002: Insufficient validation of untrusted input in Google Lens. Reported by Google on 2026-06-09

[N/A][521934304] Low CVE-2026-18003: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-09

[N/A][522280805] Low CVE-2026-18004: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-10

[N/A][522300211] Low CVE-2026-18005: Inappropriate implementation in WebXR. Reported by Google on 2026-06-10

[N/A][522396262] Low CVE-2026-18006: Inappropriate implementation in Google Lens. Reported by Google on 2026-06-10

[N/A][522404101] Low CVE-2026-18007: Inappropriate implementation in Input. Reported by Google on 2026-06-10

[N/A][522412676] Low CVE-2026-18008: Inappropriate implementation in Settings. Reported by Google on 2026-06-10

[N/A][522419718] Low CVE-2026-18009: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-10

[N/A][522419819] Low CVE-2026-18010: Inappropriate implementation in Passwords. Reported by Google on 2026-06-10

[N/A][522479633] Low CVE-2026-18011: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-11

[N/A][522938824] Low CVE-2026-18012: Use after free in PDFium. Reported by Google on 2026-06-11

[N/A][523245998] Low CVE-2026-18013: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-12

[N/A][523248021] Low CVE-2026-18014: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-12

[N/A][523698428] Low CVE-2026-18015: Inappropriate implementation in Tint. Reported by Google on 2026-06-13

[N/A][523708527] Low CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-13

[N/A][523731236] Low CVE-2026-18017: Use after free in Dawn. Reported by Google on 2026-06-14

[N/A][524467747] Low CVE-2026-18018: Inappropriate implementation in Updater. Reported by Google on 2026-06-16

[N/A][525691898] Low CVE-2026-18019: Side-channel information leakage in Media. Reported by Google on 2026-06-19
 
Google Chrome 151.0.7922.108/.109 Stable Channel Update for Desktop
The Stable channel has been updated to 151.0.7922.108/.109 for Windows and Mac and 151.0.7922.108 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

This update includes 41 security fixes.
 
Google Chrome 151.0.7922.137/.138 Stable Channel Update for Desktop
This update includes 5 security fixes. Please see the Chrome Security Page for more information.

[$500][535000102] High CVE-2026-19556: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-07-15
[N/A][534867485] High CVE-2026-19557: Use after free in TabStrip. Reported by Google on 2026-07-14
[N/A][536676756] High CVE-2026-19558: Use after free in Extensions. Reported by @bean5oup on 2026-07-20
[N/A][540100588] High CVE-2026-19559: Use after free in HTML. Reported by Google on 2026-07-28
[N/A][540482895] High CVE-2026-19560: Use after free in Blink. Reported by WinD39 - Huynh Dinh Vu on 2026-07-30
 
Google Chrome 151.0.7922.169/.170 Stable Channel Update for Desktop
This update includes 15 security fixes. Please see the Chrome Security Page for more information.

[N/A][534923522] Critical CVE-2026-76034: Buffer overflow in WebGL. Reported by Google on 2026-07-15

[N/A][540087398] Critical CVE-2026-76036: Buffer overflow in Dawn. Reported by Google on 2026-07-28

[N/A][516715010] High CVE-2026-76033: Inappropriate implementation in CORS. Reported by Google on 2026-05-26

[N/A][517612295] High CVE-2026-76037: Link following in CredentialProvider. Reported by Google on 2026-05-28

[N/A][522732244] High CVE-2026-76044: Race condition in USB. Reported by Google on 2026-06-11

[N/A][525167753] High CVE-2026-76039: Incorrect reference resolution in Core. Reported by Google on 2026-06-18

[N/A][534862220] High CVE-2026-76040: Use after free in Browser. Reported by Google on 2026-07-14

[N/A][536439844] High CVE-2026-76035: Inappropriate implementation in Media. Reported by Google on 2026-07-19

[N/A][536460270] High CVE-2026-76042: Use of uninitialized resource in GPU. Reported by Google on 2026-07-19

[N/A][536581050] High CVE-2026-76046: Buffer overflow in ANGLE. Reported by Google on 2026-07-19

[TBD][539350801] High CVE-2026-76043: Incorrect calculation in V8. Reported by Raghav Maheshwari on 2026-07-27

[N/A][540027341] High CVE-2026-76041: Information leak in Skia. Reported by Google on 2026-07-28

[TBD][541251902] High CVE-2026-76047: Type confusion in V8. Reported by ywatanabee on 2026-07-31

[TBD][541926503] High CVE-2026-76038: Type confusion in V8. Reported by un3xploitable && GF on 2026-08-03

[TBD][543082390] High CVE-2026-76045: Use after free in WebGL. Reported by OpenAI Codex Security (amyb) on 2026-08-05
 
Google Chrome 151.0.7922.173/.174 Stable Channel Update for Desktop
This update includes 7 security fixes. Please see the Chrome Security Page for more information.

[N/A][522819252] Critical CVE-2026-76017: Use after free in Chromoting. Reported by Google on 2026-06-11

[N/A][513757918] High CVE-2026-76018: Privilege elevation in Import. Reported by Google on 2026-05-16

[TBD][539032888] High CVE-2026-76019: Incorrect authorization in Workers. Reported by Anonymous on 2026-07-26

[TBD][541837151] High CVE-2026-76020: Race condition in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-03

[N/A][541854084] High CVE-2026-76021: Use after free in DOM. Reported by Google BigSleep@Grape on 2026-08-02

[TBD][543798025] High CVE-2026-76022: Buffer overflow in Network. Reported by 0xAlessandro on 2026-08-07

[TBD][545124048] High CVE-2026-76023: Improper resource control in Linux Toolkit Theming. Reported by Keita Sode and Daisuke Hatakeyama of SYZD Research on 2026-08-11
 
Chrome 152.0.7977.65 has arrived.
This update includes 327 security fixes. Please see the Chrome Security Page for more information.

[$25,000][496807874] Critical CVE-2026-79282: Use after free in ANGLE. Reported by Goodluck on 2026-03-27

[N/A][516427761] Critical CVE-2026-79290: Use after free in Aura. Reported by Google on 2026-05-25

[N/A][516764384] Critical CVE-2026-79054: Use after free in Chromecast. Reported by Google on 2026-05-26

[N/A][516777082] Critical CVE-2026-79121: Improper input validation in Chromecast. Reported by Google on 2026-05-26

[N/A][516988476] Critical CVE-2026-79224: Use after free in Chromecast. Reported by Google on 2026-05-27

[N/A][517518019] Critical CVE-2026-79052: Use after free in Aura. Reported by Google on 2026-05-28

[N/A][518006007] Critical CVE-2026-79150: Use after free in Views. Reported by Google on 2026-05-29

[N/A][522082472] Critical CVE-2026-78935: Use of uninitialized variable in Mobile. Reported by Google on 2026-06-10

[N/A][523704817] Critical CVE-2026-79012: Use after free in Safebrowsing. Reported by Google on 2026-06-13

[N/A][532921800] Critical CVE-2026-79200: Use after free in Aura. Reported by Google on 2026-07-09

[$1,000][532617619] High CVE-2026-78989: Out of bounds read in ANGLE. Reported by Đặng Thế Tuyến on 2026-07-09

[$500][508638064] High CVE-2026-79069: Memory corruption in Tint. Reported by andryskowski.michal on 2026-05-01

[N/A][498885920] High CVE-2026-79175: Type confusion in Accessibility. Reported by Google on 2026-04-02

[N/A][500311587] High CVE-2026-79218: Incorrect authorization in Sandbox. Reported by Google on 2026-04-07

[N/A][501892500] High CVE-2026-79195: Use after free in Script. Reported by Google on 2026-04-12

[N/A][513261751] High CVE-2026-78939: Use after free in Chromecast. Reported by Google on 2026-05-14

[N/A][515470739] High CVE-2026-79194: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][515473074] High CVE-2026-79247: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][516947491] High CVE-2026-79219: Use after free in Bluetooth. Reported by Google on 2026-05-27

[N/A][517515945] High CVE-2026-79047: Use after free in Views. Reported by Google on 2026-05-28

[N/A][517519352] High CVE-2026-79292: Integer overflow in Chromecast. Reported by Google on 2026-05-28

[N/A][517527943] High CVE-2026-78986: Uninitialized resource in GPU. Reported by Google on 2026-05-28

[N/A][517548647] High CVE-2026-79039: Use after free in Mobile. Reported by Google on 2026-05-28

[N/A][517550232] High CVE-2026-78934: Race condition in ReadAloud. Reported by Google on 2026-05-28

[N/A][517736936] High CVE-2026-79011: UI misrepresentation in Browser. Reported by Google on 2026-05-29

[N/A][517742721] High CVE-2026-78911: Incorrect authorization in USB. Reported by Google on 2026-05-29

[N/A][517959443] High CVE-2026-79257: Use after free in Views. Reported by Google on 2026-05-29

[N/A][521285077] High CVE-2026-79202: Use after free in Chromecast. Reported by Google on 2026-06-08

[N/A][521502218] High CVE-2026-79212: Missing authorization in Passwords. Reported by Google on 2026-06-08

[N/A][521942358] High CVE-2026-79183: Use after free in Accessibility. Reported by Google on 2026-06-09

[N/A][522294538] High CVE-2026-79155: Race condition in FileSystem. Reported by Google on 2026-06-10

[N/A][523095011] High CVE-2026-79093: Incorrect authorization in Paint. Reported by Google on 2026-06-12

[N/A][523266585] High CVE-2026-79019: Out of bounds write in ANGLE. Reported by Google on 2026-06-12

[N/A][523296105] High CVE-2026-79187: Use after free in WebRTC. Reported by Google on 2026-06-12

[N/A][523714535] High CVE-2026-79288: Improper input validation in Autofill. Reported by Google on 2026-06-14

[N/A][523717796] High CVE-2026-79130: Buffer overflow in ANGLE. Reported by Google on 2026-06-14

[N/A][523723064] High CVE-2026-78965: Uninitialized resource in ANGLE. Reported by Google on 2026-06-14

[N/A][523738212] High CVE-2026-79117: Race condition in WebAppInstalls. Reported by Google on 2026-06-14

[N/A][524698525] High CVE-2026-79082: Incorrect authorization in Transactions Platform. Reported by Google on 2026-06-16

[N/A][525683797] High CVE-2026-79111: Improper input validation in Dawn. Reported by Google on 2026-06-19

[N/A][528397177] High CVE-2026-79072: Improper state validation in Performance. Reported by Google on 2026-06-27

[N/A][529509587] High CVE-2026-79142: Buffer overflow in ANGLE. Reported by Google on 2026-06-30

[N/A][529991907] High CVE-2026-78948: Buffer overflow in WebGL. Reported by Google on 2026-07-01

[N/A][532904047] High CVE-2026-78908: Information leak in Canvas. Reported by Google on 2026-07-09

[N/A][532914190] High CVE-2026-78895: Information leak in Paint. Reported by Google on 2026-07-09

[N/A][532988552] High CVE-2026-79043: Out of bounds write in ANGLE. Reported by Google on 2026-07-09

[N/A][534468209] High CVE-2026-79235: Use after free in WebGL. Reported by Google on 2026-07-13

[N/A][534591074] High CVE-2026-79232: Use after free in Aura. Reported by Google on 2026-07-14

[N/A][535379043] High CVE-2026-79118: Uninitialized resource in ANGLE. Reported by Google on 2026-07-16

[TBD][535876894] High CVE-2026-79174: Incorrect authorization in Extensions. Reported by 章鱼哥@aipyaipy.com on 2026-07-17

[N/A][536428615] High CVE-2026-78900: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536444272] High CVE-2026-79188: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536505721] High CVE-2026-79189: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536531630] High CVE-2026-79048: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536532605] High CVE-2026-79240: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536568319] High CVE-2026-79014: Race condition in Autofill. Reported by Google on 2026-07-19

[N/A][536606137] High CVE-2026-79198: Use after free in Platform. Reported by Google on 2026-07-19

[N/A][536626343] High CVE-2026-79131: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536636648] High CVE-2026-79149: Use after free in ANGLE. Reported by Google on 2026-07-19

[N/A][536659904] High CVE-2026-79275: Use after free in ANGLE. Reported by Google on 2026-07-20

[N/A][536681676] High CVE-2026-79138: Out of bounds write in ANGLE. Reported by Google on 2026-07-20

[N/A][537109028] High CVE-2026-79026: Use after free in Extensions. Reported by Google on 2026-07-21

[TBD][537233963] High CVE-2026-79027: Use after free in WebRTC. Reported by Mozilla on 2026-07-21

[N/A][537835609] High CVE-2026-78904: Type confusion in ANGLE. Reported by Google on 2026-07-22

[TBD][540430406] High CVE-2026-78899: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-07-29

[N/A][540870921] High CVE-2026-78954: Incorrect authorization in Extensions. Reported by Google on 2026-07-30

[TBD][543707066] High CVE-2026-79274: Information leak in GPU. Reported by weihengqiuu on 2026-08-07

[TBD][545767601] High CVE-2026-78938: Type confusion in V8. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-08-12

[TBD][545820931] High CVE-2026-78952: Out of bounds write in Crashpad. Reported by Brendan Dolan-Gavitt, XBOW on 2026-08-13

[TBD][546670199] High CVE-2026-79236: Type confusion in V8. Reported by Zhenpeng (Leo) Lin on 2026-08-14

[TBD][548340637] High CVE-2026-79078: Use after free in FedCM. Reported by m0omo0d on 2026-08-18

[$8,000][495021566] Medium CVE-2026-79209: Type confusion in Animation. Reported by ochko on 2026-03-22

[$2,000][40057398] Medium CVE-2026-79030: Observable discrepancy in Autofill. Reported by Young Min Kim (@ylemkimon), CompSec Lab at Seoul National

University on 2021-09-25

[$1,000][536913431] Medium CVE-2026-79216: Buffer overflow in Blink. Reported by Found by XBOW and triaged by Andrés Luksenberg on 2026-07-20

[N/A][495579602] Medium CVE-2026-79007: Uninitialized resource in GPU. Reported by Google on 2026-03-24

[N/A][495998981] Medium CVE-2026-78893: Information leak in QUIC. Reported by Google on 2026-03-25

[N/A][496195129] Medium CVE-2026-79222: Incorrect authorization in CustomTabs. Reported by Google on 2026-03-25

[N/A][496292729] Medium CVE-2026-79071: Race condition in GPU. Reported by Google on 2026-03-25

[N/A][496395158] Medium CVE-2026-79076: Improper input validation in Sync. Reported by Google on 2026-03-26

[N/A][496401361] Medium CVE-2026-79088: Incorrect authorization in FileSystem. Reported by Google on 2026-03-26

[N/A][497017869] Medium CVE-2026-79104: Missing authorization in Sensor. Reported by Google on 2026-03-27

[N/A][497095313] Medium CVE-2026-79044: Missing authorization in WebAppInstalls. Reported by Google on 2026-03-28

[N/A][497205529] Medium CVE-2026-78958: Uninitialized resource in Skia. Reported by Google on 2026-03-28

[N/A][497269030] Medium CVE-2026-78961: Incorrect authorization in Core. Reported by Google on 2026-03-28

[N/A][497338168] Medium CVE-2026-79262: Incorrect authorization in Network. Reported by Google on 2026-03-29

[N/A][497456156] Medium CVE-2026-79106: Improper input validation in Input. Reported by Google on 2026-03-29

[N/A][497538341] Medium CVE-2026-79176: UI misrepresentation in Extensions. Reported by Google on 2026-03-29

[N/A][497637694] Medium CVE-2026-78966: Externally controlled reference in QUIC. Reported by Google on 2026-03-30

[N/A][497646947] Medium CVE-2026-79186: Incorrect authorization in Network. Reported by Google on 2026-03-30

[N/A][497839983] Medium CVE-2026-79267: Race condition in Workers. Reported by Google on 2026-03-30

[N/A][497854976] Medium CVE-2026-79016: Observable discrepancy in SVG. Reported by Google on 2026-03-30

[N/A][497869284] Medium CVE-2026-79010: Operation on a resource after expiration or release in Network. Reported by Google on 2026-03-30

[N/A][497940451] Medium CVE-2026-79286: Missing authorization in CustomTabs. Reported by Google on 2026-03-30

[N/A][497948894] Medium CVE-2026-78945: Use after free in Views. Reported by Google on 2026-03-30

[N/A][497957278] Medium CVE-2026-78999: Improper privilege management in Navigation. Reported by Google on 2026-03-30

[N/A][498327743] Medium CVE-2026-78941: Information leak in Core. Reported by Google on 2026-03-31

[N/A][498328139] Medium CVE-2026-79032: Improper input validation in Network. Reported by Google on 2026-03-31

[N/A][498367544] Medium CVE-2026-79109: Improper input validation in Printing. Reported by Google on 2026-04-01

[N/A][499007248] Medium CVE-2026-79256: Externally controlled reference in WebView. Reported by Google on 2026-04-02

[N/A][499068536] Medium CVE-2026-79237: Incorrect authorization in Navigation. Reported by Google on 2026-04-02

[N/A][499423269] Medium CVE-2026-78898: Incorrect authorization in Downloads. Reported by Google on 2026-04-04

[N/A][500038021] Medium CVE-2026-78985: Incorrect reference resolution in FileSystem. Reported by Google on 2026-04-06

[N/A][500492844] Medium CVE-2026-79028: Observable discrepancy in Network. Reported by Google on 2026-04-08

[N/A][501331457] Medium CVE-2026-79210: Use after free in Audio. Reported by Google on 2026-04-10

[N/A][501437087] Medium CVE-2026-79046: Race condition in Permissions. Reported by Google on 2026-04-10

[N/A][501572758] Medium CVE-2026-79129: Use after free in Sessions. Reported by Google on 2026-04-11

[N/A][501590191] Medium CVE-2026-78937: Use after free in Search. Reported by Google on 2026-04-11

[N/A][501594511] Medium CVE-2026-78987: Information leak in Canvas. Reported by Google on 2026-04-11

[N/A][501604761] Medium CVE-2026-78990: Use after free in Compositing. Reported by Google on 2026-04-11

[N/A][501637242] Medium CVE-2026-78909: Use after free in Views. Reported by Google on 2026-04-11

[N/A][501661601] Medium CVE-2026-79271: Information leak in DOM. Reported by Google on 2026-04-11

[N/A][501759192] Medium CVE-2026-79144: Information leak in Skia. Reported by Google on 2026-04-11

[N/A][501799770] Medium CVE-2026-79065: Improper input validation in Network. Reported by Google on 2026-04-12

[N/A][502082953] Medium CVE-2026-79192: Improper input validation in Variations. Reported by Google on 2026-04-13

[N/A][502101200] Medium CVE-2026-79140: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502109333] Medium CVE-2026-79128: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502139081] Medium CVE-2026-78942: Incorrect reference resolution in Loader. Reported by Google on 2026-04-13

[N/A][502232151] Medium CVE-2026-79116: Missing authorization in Viz. Reported by Google on 2026-04-13

[N/A][502344135] Medium CVE-2026-79006: Protection mechanism failure in HttpsUpgrades. Reported by Google on 2026-04-14

[N/A][502488051] Medium CVE-2026-79095: Information leak in Payments. Reported by Google on 2026-04-14

[N/A][502805441] Medium CVE-2026-79084: Inadequate encryption strength in Notifications. Reported by Google on 2026-04-15

[N/A][502888857] Medium CVE-2026-78991: Race condition in WebProtect. Reported by Google on 2026-04-15

[N/A][502918844] Medium CVE-2026-79248: Incorrect authorization in Input. Reported by Google on 2026-04-15

[TBD][503013378] Medium CVE-2026-78891: Buffer overflow in WebRTC. Reported by ngrunbaum on 2026-04-15

[N/A][503472696] Medium CVE-2026-79031: Improper resource exposure in Preload. Reported by Google on 2026-04-16

[N/A][503585863] Medium CVE-2026-79110: Missing authorization in Preload. Reported by Google on 2026-04-17

[N/A][503624894] Medium CVE-2026-79136: Incorrect authorization in ServiceWorker. Reported by Google on 2026-04-17

[N/A][503847023] Medium CVE-2026-78907: Incorrect authorization in WebProtect. Reported by Google on 2026-04-17

[N/A][504226770] Medium CVE-2026-79087: Injection in Chrome Tabs. Reported by Google on 2026-04-19

[N/A][504356442] Medium CVE-2026-79231: Buffer overflow in Media. Reported by Google on 2026-04-19

[N/A][504633668] Medium CVE-2026-78969: Uninitialized resource in Video. Reported by Google on 2026-04-20

[N/A][505951430] Medium CVE-2026-79137: Incorrect authorization in Extensions. Reported by Google on 2026-04-24

[N/A][505967344] Medium CVE-2026-79057: Race condition in Start. Reported by Google on 2026-04-24

[N/A][505991181] Medium CVE-2026-78894: Race condition in Payments. Reported by Google on 2026-04-24

[N/A][507483993] Medium CVE-2026-79264: Incorrect reference resolution in Preload. Reported by Google on 2026-04-28

[N/A][511260796] Medium CVE-2026-78910: Buffer overflow in V8. Reported by Google on 2026-05-08

[N/A][511736672] Medium CVE-2026-79066: Improper input validation in Navigation. Reported by Google on 2026-05-10

[N/A][511794959] Medium CVE-2026-79255: Improper input validation in WebRTC. Reported by Google on 2026-05-10

[N/A][511804361] Medium CVE-2026-79086: Missing authorization in CustomTabs. Reported by Google on 2026-05-10

[N/A][511806043] Medium CVE-2026-79038: Incorrect authorization in WebProtect. Reported by Google on 2026-05-10

[N/A][511819962] Medium CVE-2026-78940: Improper initialization in Network. Reported by Google on 2026-05-10

[N/A][511822878] Medium CVE-2026-79107: Incorrect authorization in TabGroups. Reported by Google on 2026-05-10

[N/A][512971896] Medium CVE-2026-79120: Uninitialized resource in ANGLE. Reported by Google on 2026-05-13

[N/A][513048462] Medium CVE-2026-79270: Uninitialized resource in ANGLE. Reported by Google on 2026-05-14

[N/A][513049445] Medium CVE-2026-79067: Missing authorization in Network. Reported by Google on 2026-05-14

[N/A][513119757] Medium CVE-2026-79213: Incorrect authorization in WebAppInstalls. Reported by Google on 2026-05-14

[N/A][513192145] Medium CVE-2026-78943: Improper input validation in Editing. Reported by Google on 2026-05-14

[N/A][513222422] Medium CVE-2026-79259: Improper input validation in Safebrowsing. Reported by Google on 2026-05-14

[N/A][513287677] Medium CVE-2026-79208: Missing authorization in HTTP2. Reported by Google on 2026-05-14

[N/A][513392351] Medium CVE-2026-79251: Improper input validation in Network. Reported by Google on 2026-05-15

[N/A][513607252] Medium CVE-2026-79226: Improper privilege management in Regional Capabilities. Reported by Google on 2026-05-15

[N/A][513608317] Medium CVE-2026-79042: Missing authorization in Payments. Reported by Google on 2026-05-15

[N/A][513608831] Medium CVE-2026-79122: Information leak in SignIn. Reported by Google on 2026-05-15

[N/A][513719741] Medium CVE-2026-79199: Incorrect authorization in Network. Reported by Google on 2026-05-16

[N/A][513737209] Medium CVE-2026-79013: Improper input validation in Sync. Reported by Google on 2026-05-16

[N/A][513745793] Medium CVE-2026-79074: Information leak in Network. Reported by Google on 2026-05-16

[N/A][513760788] Medium CVE-2026-79215: Integer overflow in WebGL. Reported by Google on 2026-05-16

[N/A][513786555] Medium CVE-2026-79049: Incorrect reference resolution in Passwords. Reported by Google on 2026-05-16

[N/A][513834155] Medium CVE-2026-79132: Improper input validation in Input. Reported by Google on 2026-05-16

[N/A][513836495] Medium CVE-2026-79201: Improper access control in Workers. Reported by Google on 2026-05-16

[N/A][513841856] Medium CVE-2026-79051: Incorrect authorization in Loader. Reported by Google on 2026-05-16

[N/A][513850062] Medium CVE-2026-79053: Missing authorization in Lighthouse. Reported by Google on 2026-05-16

[N/A][513918923] Medium CVE-2026-79285: Uninitialized resource in ANGLE. Reported by Google on 2026-05-17

[N/A][513923164] Medium CVE-2026-78906: Race condition in ANGLE. Reported by Google on 2026-05-17

[N/A][514006744] Medium CVE-2026-79250: UI misrepresentation in Navigation. Reported by Google on 2026-05-17

[N/A][514017820] Medium CVE-2026-79020: Out of bounds read in Skia. Reported by Google on 2026-05-17

[N/A][514055709] Medium CVE-2026-79217: Incorrect authorization in Mobile. Reported by Google on 2026-05-17

[N/A][514069975] Medium CVE-2026-79204: UI misrepresentation in Input. Reported by Google on 2026-05-17

[N/A][514078852] Medium CVE-2026-78912: UI misrepresentation in Browser. Reported by Google on 2026-05-17

[N/A][514439436] Medium CVE-2026-78955: Observable discrepancy in PerformanceAPIs. Reported by Google on 2026-05-18

[N/A][514454739] Medium CVE-2026-79143: Incorrect authorization in FileSystem. Reported by Google on 2026-05-19

[N/A][514508415] Medium CVE-2026-79241: Out of bounds read in GPU. Reported by Google on 2026-05-19

[N/A][514529599] Medium CVE-2026-78967: Missing authorization in BFCache. Reported by Google on 2026-05-19

[N/A][515477007] Medium CVE-2026-79214: Improper input validation in Preload. Reported by Google on 2026-05-21

[N/A][516398679] Medium CVE-2026-79228: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-25

[N/A][516665605] Medium CVE-2026-78953: Missing authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516824665] Medium CVE-2026-79229: Uninitialized resource in ANGLE. Reported by Google on 2026-05-26

[N/A][516899248] Medium CVE-2026-79002: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516921259] Medium CVE-2026-79272: Improper input validation in FindInPage. Reported by Google on 2026-05-27

[N/A][517045394] Medium CVE-2026-79127: Out of bounds write in ANGLE. Reported by Google on 2026-05-27

[N/A][517074167] Medium CVE-2026-79151: Improper input validation in Safebrowsing. Reported by Google on 2026-05-27

[N/A][517095594] Medium CVE-2026-78936: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-27

[N/A][517245017] Medium CVE-2026-78905: Type confusion in ANGLE. Reported by Google on 2026-05-27

[N/A][517364411] Medium CVE-2026-79050: Incorrect authorization in Network. Reported by Google on 2026-05-28

[N/A][517382613] Medium CVE-2026-79008: Improper input validation in GPU. Reported by Google on 2026-05-28

[N/A][517398863] Medium CVE-2026-78975: Incorrect authorization in DOM. Reported by Google on 2026-05-28

[N/A][517404644] Medium CVE-2026-79287: Observable discrepancy in Forms. Reported by Google on 2026-05-28

[N/A][517467117] Medium CVE-2026-79094: Race condition in Workers. Reported by Google on 2026-05-28

[N/A][517487890] Medium CVE-2026-79173: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-28

[N/A][517550421] Medium CVE-2026-78976: Improper input validation in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517580738] Medium CVE-2026-79276: Improper privilege management in FileSystem. Reported by Google on 2026-05-28

[N/A][517606780] Medium CVE-2026-79191: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-28

[N/A][517608454] Medium CVE-2026-79099: Missing authorization in Network. Reported by Google on 2026-05-28

[N/A][517634590] Medium CVE-2026-79024: Information leak in ServiceWorker. Reported by Google on 2026-05-28

[N/A][517655953] Medium CVE-2026-79193: Information leak in Canvas. Reported by Google on 2026-05-28

[N/A][517697155] Medium CVE-2026-79242: Observable discrepancy in HTML. Reported by Google on 2026-05-29

[N/A][517719358] Medium CVE-2026-79180: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-29

[N/A][517746687] Medium CVE-2026-79293: Information leak in Animation. Reported by Google on 2026-05-29

[N/A][517761566] Medium CVE-2026-79023: Incorrect authorization in Editing. Reported by Google on 2026-05-29

[N/A][517772510] Medium CVE-2026-79146: Information leak in CustomTabs. Reported by Google on 2026-05-29

[N/A][517774971] Medium CVE-2026-79238: Incorrect authorization in ServiceWorker. Reported by Google on 2026-05-29

[N/A][517910756] Medium CVE-2026-78949: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-29

[N/A][518023156] Medium CVE-2026-79291: Information leak in CSS. Reported by Google on 2026-05-29

[N/A][518035396] Medium CVE-2026-79283: UI misrepresentation in Geometry. Reported by Google on 2026-05-29

[N/A][518053893] Medium CVE-2026-78892: Incorrect authorization in Chromoting. Reported by Google on 2026-05-30

[N/A][518062961] Medium CVE-2026-79070: Incorrect reference resolution in Cache. Reported by Google on 2026-05-30

[N/A][518065628] Medium CVE-2026-79205: Incorrect authorization in Network. Reported by Google on 2026-05-30

[N/A][518078552] Medium CVE-2026-78903: Incomplete cleanup in SiteIsolation. Reported by Google on 2026-05-30

[N/A][518084889] Medium CVE-2026-78959: Improper handling of case sensitivity in FileSystem. Reported by Google on 2026-05-30

[N/A][518094442] Medium CVE-2026-79234: Injection in CSS. Reported by Google on 2026-05-30

[N/A][519369088] Medium CVE-2026-78983: Use after free in Views. Reported by Google on 2026-06-03

[N/A][519984038] Medium CVE-2026-79083: Improper enforcement of behavioral workflow in Media. Reported by Google on 2026-06-04

[TBD][520052954] Medium CVE-2026-78944: Use after free in DevTools. Reported by yupyon.itome on 2026-06-05

[N/A][520117546] Medium CVE-2026-79178: Incorrect authorization in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-04

[N/A][520121111] Medium CVE-2026-79059: Information leak in BFCache. Reported by Google on 2026-06-04

[N/A][520179360] Medium CVE-2026-79245: Use after free in UI. Reported by Google on 2026-06-05

[N/A][520464738] Medium CVE-2026-78978: Out of bounds read in ANGLE. Reported by Google on 2026-06-05

[N/A][520481800] Medium CVE-2026-79103: Incorrect reference resolution in Speech. Reported by Google on 2026-06-05

[N/A][520492291] Medium CVE-2026-79154: Missing authorization in DevTools. Reported by Google on 2026-06-05

[N/A][520504922] Medium CVE-2026-79230: Improper input validation in ANGLE. Reported by Google on 2026-06-05

[N/A][520516462] Medium CVE-2026-79068: Improper resource exposure in StreamsAPI. Reported by Google on 2026-06-05

[N/A][520542088] Medium CVE-2026-79269: Uninitialized resource in ANGLE. Reported by Google on 2026-06-05

[N/A][522077127] Medium CVE-2026-79085: Missing authorization in Network. Reported by Google on 2026-06-10

[N/A][522351802] Medium CVE-2026-79134: Incorrect authorization in GetUserMedia. Reported by Google on 2026-06-10

[N/A][522550059] Medium CVE-2026-79064: Use after free in Network. Reported by Google on 2026-06-11

[N/A][522791354] Medium CVE-2026-79003: Incorrect authorization in Device. Reported by Google on 2026-06-11

[N/A][522823211] Medium CVE-2026-79220: Information leak in Network. Reported by Google on 2026-06-11

[N/A][522957054] Medium CVE-2026-78951: Use after free in ServiceWorker. Reported by Google on 2026-06-11

[N/A][523232966] Medium CVE-2026-79249: Code injection in Bisection. Reported by Google on 2026-06-12

[N/A][523557855] Medium CVE-2026-79091: Use after free in Bluetooth. Reported by Google on 2026-06-13

[N/A][523661149] Medium CVE-2026-79265: Incomplete cleanup in GetUserMedia. Reported by Google on 2026-06-13

[N/A][523716748] Medium CVE-2026-78913: Use after free in Chromoting. Reported by Google on 2026-06-14

[N/A][524418836] Medium CVE-2026-79258: Incorrect authorization in WebXR. Reported by Google on 2026-06-16

[TBD][524520965] Medium CVE-2026-79211: Incorrect authorization in USB. Reported by hongan on 2026-06-16

[N/A][524541667] Medium CVE-2026-79252: Information leak in ServiceWorker. Reported by Google on 2026-06-16

[N/A][524822825] Medium CVE-2026-78962: Uninitialized resource in WebXR. Reported by Google on 2026-06-17

[N/A][525686865] Medium CVE-2026-78901: Race condition in V8. Reported by Google on 2026-06-19

[N/A][525689847] Medium CVE-2026-79097: Use after free in V8. Reported by Google on 2026-06-19

[N/A][532162132] Medium CVE-2026-79227: Type confusion in DevTools. Reported by Google on 2026-07-07

[N/A][532182486] Medium CVE-2026-79203: Improper input validation in DevTools. Reported by Google on 2026-07-07

[N/A][532914769] Medium CVE-2026-79033: Insufficient control flow management in DevTools. Reported by Google on 2026-07-09

[N/A][532917452] Medium CVE-2026-79139: Improper input validation in Media. Reported by Google on 2026-07-09

[N/A][532923954] Medium CVE-2026-79221: Uninitialized resource in Dawn. Reported by Google on 2026-07-09

[N/A][532957785] Medium CVE-2026-79034: Information leak in CORS. Reported by Google on 2026-07-09

[N/A][533093250] Medium CVE-2026-79075: Information leak in Geolocation. Reported by Google on 2026-07-09

[TBD][533917984] Medium CVE-2026-78960: Information leak in Extensions. Reported by Oran Simhony from Palo Alto Networks on 2026-07-12

[N/A][535374213] Medium CVE-2026-78984: Uninitialized resource in GPU. Reported by Google on 2026-07-16

[N/A][536428842] Medium CVE-2026-78963: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536428988] Medium CVE-2026-79004: Out of bounds read in Media. Reported by Google on 2026-07-19

[N/A][536444242] Medium CVE-2026-79182: Improper input validation in Media. Reported by Google on 2026-07-19

[TBD][536526176] Medium CVE-2026-79185: Information leak in DOM. Reported by avlidienbrunn on 2026-07-19

[N/A][536662911] Medium CVE-2026-79073: Improper state validation in Parser. Reported by Google on 2026-07-20

[N/A][537145191] Medium CVE-2026-79266: Use after free in DevTools. Reported by Google on 2026-07-21

[N/A][537846307] Medium CVE-2026-79025: Improper input validation in Workers. Reported by Google on 2026-07-22

[TBD][538969297] Medium CVE-2026-79141: Incorrect authorization in Browser. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-07-25

[$1,000][503048520] Low CVE-2026-78974: UI misrepresentation in Linux Toolkit Theming. Reported by Francesco Topol on 2026-04-16

[N/A][497232609] Low CVE-2026-79055: Information leak in Sharing. Reported by Google on 2026-03-28

[N/A][497256260] Low CVE-2026-79263: Race condition in Extensions. Reported by Google on 2026-03-28

[N/A][497493136] Low CVE-2026-79124: Information leak in Intents. Reported by Google on 2026-03-29

[N/A][497499482] Low CVE-2026-79184: Missing authorization in Preload. Reported by Google on 2026-03-29

[N/A][497876969] Low CVE-2026-79289: Improper control of a resource through its lifetime in Workers. Reported by Google on 2026-03-30

[N/A][500484520] Low CVE-2026-79001: Information leak in Bluetooth. Reported by Google on 2026-04-07

[N/A][501416859] Low CVE-2026-79077: Incorrect authorization in WebProtect. Reported by Google on 2026-04-10

[TBD][501881082] Low CVE-2026-78950: Integer overflow in WebRTC. Reported by Ashutosh on 2026-04-12

[N/A][502252964] Low CVE-2026-79196: Race condition in Editing. Reported by Google on 2026-04-13

[N/A][502514083] Low CVE-2026-79000: Improper input validation in DeviceBoundSessionCredentials. Reported by Google on 2026-04-14

[N/A][503720291] Low CVE-2026-78979: Race condition in Core. Reported by Google on 2026-04-17

[N/A][506539337] Low CVE-2026-79181: Observable discrepancy in Glic. Reported by Google on 2026-04-26

[N/A][513172858] Low CVE-2026-79190: Incorrect authorization in Extensions. Reported by Google on 2026-05-14

[N/A][513361380] Low CVE-2026-79206: Out of bounds read in FileSystem. Reported by Google on 2026-05-15

[N/A][513486883] Low CVE-2026-78897: Missing authorization in BrowserTag. Reported by Google on 2026-05-15

[N/A][513688690] Low CVE-2026-79119: Use after free in PDF. Reported by Google on 2026-05-15

[N/A][513792983] Low CVE-2026-79089: Race condition in Transactions Platform. Reported by Google on 2026-05-16

[N/A][513969378] Low CVE-2026-79147: Information leak in Skia. Reported by Google on 2026-05-17

[N/A][514010111] Low CVE-2026-79098: UI misrepresentation in PermissionElement. Reported by Google on 2026-05-17

[N/A][514038302] Low CVE-2026-79022: UI misrepresentation in Transactions Platform. Reported by Google on 2026-05-17

[N/A][514061923] Low CVE-2026-79233: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-17

[N/A][514408247] Low CVE-2026-79261: Incorrect authorization in Controls. Reported by Google on 2026-05-18

[N/A][516864349] Low CVE-2026-78977: Uninitialized resource in GPU. Reported by Google on 2026-05-26

[N/A][516950646] Low CVE-2026-79040: Uninitialized resource in GPU. Reported by Google on 2026-05-27

[N/A][517167020] Low CVE-2026-79273: Incorrect reference resolution in WebView. Reported by Google on 2026-05-27

[TBD][517394060] Low CVE-2026-79243: Improper input validation in ReadingList. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[TBD][517395590] Low CVE-2026-79123: Improper input validation in NTP Footer. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[N/A][517540292] Low CVE-2026-79005: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517673944] Low CVE-2026-79090: Improper privilege management in Actor. Reported by Google on 2026-05-29

[N/A][517718241] Low CVE-2026-78946: Incorrect authorization in Select. Reported by Google on 2026-05-29

[N/A][518125889] Low CVE-2026-78968: Missing authorization in Core. Reported by Google on 2026-05-30

[N/A][518249083] Low CVE-2026-79041: Missing authorization in Browser. Reported by Google on 2026-05-30

[N/A][519210950] Low CVE-2026-79284: UI misrepresentation in Core. Reported by Google on 2026-06-02

[N/A][519229463] Low CVE-2026-78896: Information leak in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][519242511] Low CVE-2026-79058: Missing authorization in Passwords. Reported by Google on 2026-06-02

[N/A][519246298] Low CVE-2026-79009: UI misrepresentation in UI. Reported by Google on 2026-06-02

[N/A][519254827] Low CVE-2026-79060: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][520002854] Low CVE-2026-79177: Incorrect authorization in Media. Reported by Google on 2026-06-04

[N/A][520016142] Low CVE-2026-78956: Type confusion in V8. Reported by Google on 2026-06-04

[TBD][520781436] Low CVE-2026-79239: Out of bounds read in Tint. Reported by Michal Andryskowski, Imperial College London on 2026-06-07

[N/A][522291712] Low CVE-2026-79015: Improper input validation in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522304549] Low CVE-2026-79108: UI misrepresentation in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-10

[N/A][522418913] Low CVE-2026-79056: Use after free in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522803735] Low CVE-2026-79018: Information leak in FoldableAPIs. Reported by Google on 2026-06-11

[N/A][523237735] Low CVE-2026-78980: Improper input validation in ReaderMode. Reported by Google on 2026-06-12

[N/A][523313378] Low CVE-2026-78947: Incomplete cleanup in Chromium. Reported by Microsoft Edge on 2026-06-12

[N/A][523572877] Low CVE-2026-79244: Use after free in Animation. Reported by Google on 2026-06-13

[TBD][524864599] Low CVE-2026-79112: Out of bounds read in Skia. Reported by Quan Huynh x Amaterasu on 2026-06-17

[N/A][525311654] Low CVE-2026-79246: Information leak in DataTransfer. Reported by Google on 2026-06-18

[TBD][530816571] Low CVE-2026-79223: Integer overflow in Chromium. Reported by Youngjin Ju on 2026-07-03

[N/A][531245718] Low CVE-2026-79045: Type confusion in V8. Reported by Google on 2026-07-04

[N/A][531297707] Low CVE-2026-79197: Use after free in V8. Reported by Google on 2026-07-05

[N/A][532303080] Low CVE-2026-79148: Off-by-one error in DevTools. Reported by Google on 2026-07-08

[N/A][533001362] Low CVE-2026-79125: Information leak in XR. Reported by Google on 2026-07-09

[N/A][533014006] Low CVE-2026-79207: Information leak in Passwords. Reported by Google on 2026-07-09

[N/A][533021205] Low CVE-2026-79017: Race condition in Extensions. Reported by Google on 2026-07-09

[N/A][533046298] Low CVE-2026-79105: Improper input validation in Mobile. Reported by Google on 2026-07-09

[N/A][533059149] Low CVE-2026-79225: Incorrect authorization in Browser. Reported by Google on 2026-07-09

[N/A][533060125] Low CVE-2026-79021: Missing authorization in InterestGroups. Reported by Google on 2026-07-09

[N/A][533075126] Low CVE-2026-79133: Incorrect authorization in Forms. Reported by Google on 2026-07-09

[N/A][533079345] Low CVE-2026-79179: Incorrect authorization in DOM. Reported by Google on 2026-07-09

[N/A][533083384] Low CVE-2026-79152: Incorrect authorization in CustomTabs. Reported by Google on 2026-07-09

[N/A][533121405] Low CVE-2026-78981: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533123348] Low CVE-2026-78957: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533408915] Low CVE-2026-79126: Incorrect provision of specified functionality in Proxy. Reported by Google on 2026-07-10

[N/A][533418127] Low CVE-2026-78915: Race condition in Enterprise. Reported by Google on 2026-07-10

[N/A][533511921] Low CVE-2026-79253: Improper input validation in Network. Reported by Google on 2026-07-10

[N/A][533511967] Low CVE-2026-79260: Improper input validation in Cookies. Reported by Google on 2026-07-10

[N/A][534556413] Low CVE-2026-79254: Incorrect reference resolution in CustomTabs. Reported by Google on 2026-07-14

[N/A][536166543] Low CVE-2026-78914: Uninitialized resource in Skia. Reported by Google on 2026-07-18

[N/A][539341100] Low CVE-2026-78964: Use after free in Sync. Reported by Google on 2026-07-27
 
Google Chrome 152.0.7977.75/.76 Stable Channel Update for Desktop
This update includes 26 security fixes. Please see the Chrome Security Page for more information.

[N/A][522307103] Critical CVE-2026-84353: Use after free in Shared Tab Groups. Reported by Google on 2026-06-10

[N/A][546260492] Critical CVE-2026-84352: Use after free in WebGL. Reported by Google on 2026-08-14

[N/A][498839176] High CVE-2026-84354: Incorrect authorization in FileSystem. Reported by Google on 2026-04-02

[N/A][514078656] High CVE-2026-84359: Information leak in Skia. Reported by Google on 2026-05-17

[N/A][523208474] High CVE-2026-84357: Improper input validation in Omnibox. Reported by Google on 2026-06-12

[N/A][533534913] High CVE-2026-84324: Use after free in Proxy. Reported by Google on 2026-07-10

[N/A][537105664] High CVE-2026-84349: Use after free in Browser. Reported by Google on 2026-07-21

[TBD][547936520] High CVE-2026-84326: Uninitialized resource in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17

[N/A][549311485] High CVE-2026-84333: Use after free in Dawn. Reported by Google on 2026-08-19

[TBD][551593376] High CVE-2026-84351: Buffer overflow in GPU. Reported by Cassio Lima on 2026-08-24

[N/A][553117928] High CVE-2026-84325: Improper input validation in DataTransfer. Reported by Google on 2026-08-26

[N/A][498710886] Medium CVE-2026-84328: Missing authorization in FileSystem. Reported by Google on 2026-04-01

[N/A][501679156] Medium CVE-2026-84347: Use after free in WebRTC. Reported by Google on 2026-04-11

[N/A][502411391] Medium CVE-2026-84323: Missing authorization in FileSystem. Reported by Google on 2026-04-14

[N/A][511774376] Medium CVE-2026-84355: Incorrect authorization in Navigation. Reported by Google on 2026-05-10

[N/A][514006886] Medium CVE-2026-84358: Improper privilege management in Downloads. Reported by Google on 2026-05-17

[N/A][514489238] Medium CVE-2026-84332: Incorrect authorization in SiteSettings. Reported by Google on 2026-05-19

[N/A][517091927] Medium CVE-2026-84330: UI misrepresentation in FullScreen. Reported by Google on 2026-05-27

[N/A][517798926] Medium CVE-2026-84334: Incorrect authorization in Chromoting. Reported by Google on 2026-05-29

[N/A][518100026] Medium CVE-2026-84348: Information leak in MediaCapture. Reported by Google on 2026-05-30

[N/A][522302504] Medium CVE-2026-84335: Incorrect authorization in TabStrip. Reported by Google on 2026-06-10

[N/A][498725213] Low CVE-2026-84327: Incorrect authorization in Autofill. Reported by Google on 2026-04-01

[N/A][498850269] Low CVE-2026-84329: Confused deputy in CredentialProvider. Reported by Google on 2026-04-02

[TBD][503787232] Low CVE-2026-84356: UI misrepresentation in FullScreen. Reported by Francesco Topol (k4tedu) on 2026-04-18

[N/A][513713427] Low CVE-2026-84350: Use after free in TabStrip. Reported by Google on 2026-05-16

[N/A][521753402] Low CVE-2026-84331: Incorrect authorization in Actor. Reported by Google on 2026-06-09
 
Google Chrome 152.0.7977.82/.83 Stable Channel Update for Desktop
This update includes 12 security fixes. Please see the Chrome Security Page for more information.

[$1,000][542403045] High CVE-2026-85046: Type confusion in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-04
[N/A][502304489] High CVE-2026-85052: Out of bounds read in CrashReporting. Reported by Google on 2026-04-13
[N/A][533502257] High CVE-2026-85043: Incomplete cleanup in Network. Reported by Google on 2026-07-10
[TBD][540357382] High CVE-2026-85048: Use after free in Compositing. Reported by Ngoc Hieu on 2026-07-29
[TBD][547819997] High CVE-2026-85045: Race condition in V8. Reported by Brendan Dolan-Gavitt, XBOW on 2026-08-17
[N/A][549350408] High CVE-2026-85050: Out of bounds write in WebGL. Reported by Google on 2026-08-20
[TBD][552689418] High CVE-2026-85053: Improper resource exposure in CacheStorage. Reported by Salvatore Gulizia (Serotav) on 2026-08-26
[N/A][553119925] High CVE-2026-85042: Use after free in DevTools. Reported by Google on 2026-08-26
[N/A][553345874] High CVE-2026-85049: Use after free in Skia. Reported by Google on 2026-08-27
[N/A][553449113] High CVE-2026-85051: Type confusion in Compositing. Reported by Google on 2026-08-27
[N/A][513790581] Medium CVE-2026-85047: Improper input validation in Transactions Platform. Reported by Google on 2026-05-16
[N/A][517482830] Medium CVE-2026-85044: Use of released resource in Mobile. Reported by Google on 2026-05-28
 
Google Chrome 153.0.8010.36/.37 Stable Channel Update for Desktop
This update includes 230 security fixes. Please see the Chrome Security Page for more information.

[$2,500][544163112] Critical CVE-2026-87464: Use after free in WebGL. Reported by Lexi Groves (49016) on 2026-08-08
[N/A][546252753] Critical CVE-2026-87488: Use after free in WebGL. Reported by Google on 2026-08-14
[N/A][548127218] Critical CVE-2026-87438: Out of bounds write in WebGL. Reported by Google on 2026-08-18
[N/A][548130125] Critical CVE-2026-87527: Buffer overflow in WebGL. Reported by Google on 2026-08-18
[TBD][553770012] Critical CVE-2026-87628: Use after free in Cast. Reported by Hafiizh on 2026-08-28
[$2,500][541715128] High CVE-2026-87512: Use after free in ANGLE. Reported by weihengqiuu on 2026-08-02
[$500][540817065] High CVE-2026-87585: Double free in PDFium. Reported by Jeongkihyun on 2026-07-30
[TBD][489489002] High CVE-2026-87444: Memory corruption in Codecs. Reported by Casper Woudenberg on 2026-03-03
[N/A][503464711] High CVE-2026-87447: Incorrect authorization in Network. Reported by Google on 2026-04-16
[N/A][513458719] High CVE-2026-87440: Out of bounds read in Media. Reported by Google on 2026-05-15
[N/A][516996291] High CVE-2026-87633: Use after free in Views. Reported by Google on 2026-05-27
[N/A][517336350] High CVE-2026-87525: Out of bounds read in Chromoting. Reported by Google on 2026-05-28
[N/A][517371367] High CVE-2026-87578: Use after free in Receiver. Reported by Google on 2026-05-28
[N/A][517581661] High CVE-2026-87517: Race condition in Mobile. Reported by Google on 2026-05-28
[N/A][522546457] High CVE-2026-87524: Use after free in Core. Reported by Google on 2026-06-11
[N/A][523277481] High CVE-2026-87569: Missing authorization in Views. Reported by Google on 2026-06-12
[N/A][524423633] High CVE-2026-87554: Race condition in Chromoting. Reported by Google on 2026-06-16
[N/A][524453236] High CVE-2026-87467: Race condition in Updater. Reported by Google on 2026-06-16
[TBD][529123409] High CVE-2026-87492: Incorrect authorization in DevTools. Reported by Avadhut Mahamuni on 2026-06-29
[N/A][529878021] High CVE-2026-87520: Use after free in Dawn. Reported by Google on 2026-06-30
[N/A][532916987] High CVE-2026-87514: Use after free in Views. Reported by Google on 2026-07-09
[N/A][534912743] High CVE-2026-87650: Out of bounds read in WebGL. Reported by Google on 2026-07-14
[N/A][536434693] High CVE-2026-87596: Out of bounds read in ANGLE. Reported by Google on 2026-07-19
[N/A][536444790] High CVE-2026-87654: Buffer overflow in ANGLE. Reported by Google on 2026-07-19
[N/A][536648007] High CVE-2026-87604: Out of bounds read in ANGLE. Reported by Google on 2026-07-19
[N/A][536664909] High CVE-2026-87621: Out of bounds write in ANGLE. Reported by Google on 2026-07-20
[N/A][536673946] High CVE-2026-87647: Uninitialized resource in GPU. Reported by Google on 2026-07-20
[TBD][539754136] High CVE-2026-87646: Use after free in Web Authentication. Reported by h3ee on 2026-07-28
[N/A][540019091] High CVE-2026-87500: Improper validation of array index in ANGLE. Reported by Google on 2026-07-28
[N/A][540021969] High CVE-2026-87572: Injection in DevTools. Reported by Google on 2026-07-28
[N/A][540058837] High CVE-2026-87460: Use after free in Platform. Reported by Google on 2026-07-28
[N/A][542756749] High CVE-2026-87542: Use after free in Input. Reported by Google BigSleep@Grape on 2026-08-05
[TBD][544415098] High CVE-2026-87639: Use after free in WebPackaging. Reported by OpenAI Codex Security (amyb) on 2026-08-09
[TBD][547426657] High CVE-2026-87552: Missing authorization in TrustedWebActivities. Reported by juddrouillon0 on 2026-08-16
[TBD][550141694] High CVE-2026-87651: Incorrect authorization in Paint. Reported by OGINOME Tomohito on 2026-08-21
[TBD][550360762] High CVE-2026-87587: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-21
[TBD][552342545] High CVE-2026-87564: Type confusion in V8. Reported by Tech Division (@taiphung) - Mobifone Digital Payment on 2026-08-25
[N/A][552413517] High CVE-2026-87498: Missing authorization in WebUI. Reported by Google on 2026-08-25
[N/A][553118043] High CVE-2026-87499: Incorrect authorization in Network. Reported by Google on 2026-08-26
[N/A][553122131] High CVE-2026-87607: Use after free in Device. Reported by Google on 2026-08-26
[N/A][553128689] High CVE-2026-87558: Use after free in Payments. Reported by Google on 2026-08-26
[N/A][553129531] High CVE-2026-87581: Use after free in Payments. Reported by Google on 2026-08-26
[N/A][553928324] High CVE-2026-87480: Use after free in Printing. Reported by Google on 2026-08-28
[TBD][554236352] High CVE-2026-87612: Type confusion in V8. Reported by ywatanabee on 2026-08-29
[TBD][554421904] High CVE-2026-87536: Use after free in V8. Reported by StinkyTuna56 on 2026-08-29
[N/A][554558968] High CVE-2026-87474: Use after free in Payments. Reported by Google on 2026-08-29
[$5,000][499206649] Medium CVE-2026-87504: Use after free in Core. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-03
[$3,000][498482618] Medium CVE-2026-87640: Out of bounds read in WebView. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-01
[$2,500][543557673] Medium CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06
[$2,000][40060525] Medium CVE-2026-87478: Observable discrepancy in Autofill. Reported by Maurice Dauer on 2022-08-07
[$2,000][483435192] Medium CVE-2026-87446: Incomplete cleanup in Extensions. Reported by Hafiizh on 2026-02-11
[$1,000][542146471] Medium CVE-2026-87657: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-03
[N/A][493322521] Medium CVE-2026-87434: Missing authorization in CORS. Reported by Google on 2026-03-17
[N/A][495429423] Medium CVE-2026-87487: Missing authorization in FileSystem. Reported by Google on 2026-03-23
[N/A][495444970] Medium CVE-2026-87453: Confused deputy in BackgroundFetch. Reported by Google on 2026-03-23
[N/A][495515356] Medium CVE-2026-87588: Use after free in Chromecast. Reported by Google on 2026-03-23
[N/A][495541478] Medium CVE-2026-87636: Type confusion in XML. Reported by Google on 2026-03-23
[N/A][495876543] Medium CVE-2026-87611: Missing authorization in FileSystem. Reported by Google on 2026-03-24
[N/A][495933780] Medium CVE-2026-87606: Missing authorization in SiteIsolation. Reported by Google on 2026-03-25
[N/A][496231550] Medium CVE-2026-87456: Uninitialized resource in Media. Reported by Google on 2026-03-25
[N/A][496595299] Medium CVE-2026-87553: Improper input validation in SiteIsolation. Reported by Google on 2026-03-26
[N/A][496615345] Medium CVE-2026-87658: Information leak in Extensions. Reported by Google on 2026-03-26
[N/A][496616790] Medium CVE-2026-87465: Incorrect authorization in Downloads. Reported by Google on 2026-03-26
[N/A][497093426] Medium CVE-2026-87515: Incorrect authorization in FileAPI. Reported by Google on 2026-03-28
[N/A][497111188] Medium CVE-2026-87547: Incorrect reference resolution in FileSystem. Reported by Google on 2026-03-28
[N/A][497443419] Medium CVE-2026-87442: Confused deputy in Prerender. Reported by Google on 2026-03-29
[N/A][497551905] Medium CVE-2026-87506: Privilege elevation in WebUI. Reported by Google on 2026-03-29
[N/A][497574154] Medium CVE-2026-87433: Race condition in FileAPI. Reported by Google on 2026-03-30
[N/A][497635917] Medium CVE-2026-87557: Missing authorization in LocalNetworkAccess. Reported by Google on 2026-03-30
[N/A][497837188] Medium CVE-2026-87457: Race condition in Updater. Reported by Google on 2026-03-30
[N/A][497986036] Medium CVE-2026-87503: Inappropriate implementation in Downloads. Reported by Google on 2026-03-31
[N/A][498730641] Medium CVE-2026-87481: Incorrect authorization in WebView. Reported by Google on 2026-04-01
[N/A][498732709] Medium CVE-2026-87537: Missing authorization in Extensions. Reported by Google on 2026-04-01
[N/A][498869663] Medium CVE-2026-87471: Incorrect authorization in ServiceWorker. Reported by Google on 2026-04-02
[N/A][499230506] Medium CVE-2026-87485: Incorrect authorization in CORS. Reported by Google on 2026-04-03
[N/A][499425100] Medium CVE-2026-87652: Incorrect authorization in PushAPI. Reported by Google on 2026-04-04
[N/A][500094528] Medium CVE-2026-87582: Confused deputy in DataTransfer. Reported by Google on 2026-04-06
[N/A][500467033] Medium CVE-2026-87466: Incorrect authorization in Workers. Reported by Google on 2026-04-07
[N/A][501627201] Medium CVE-2026-87603: Missing authorization in FileSystem. Reported by Google on 2026-04-11
[N/A][501643868] Medium CVE-2026-87615: Race condition in Payments. Reported by Google on 2026-04-11
[N/A][501644790] Medium CVE-2026-87642: Uninitialized resource in WebGL. Reported by Google on 2026-04-11
[N/A][501700023] Medium CVE-2026-87577: Incorrect authorization in Isolated. Reported by Google on 2026-04-11
[N/A][501850947] Medium CVE-2026-87449: Cross-site request forgery in DeviceBoundSessionCredentials. Reported by Google on 2026-04-12
[N/A][501889544] Medium CVE-2026-87613: Incorrect reference resolution in Extensions. Reported by Google on 2026-04-12
[N/A][502611474] Medium CVE-2026-87645: Improper state validation in Safebrowsing. Reported by Google on 2026-04-14
[N/A][502768228] Medium CVE-2026-87443: Missing authorization in Actor. Reported by Google on 2026-04-15
[TBD][502783118] Medium CVE-2026-87630: Integer overflow in WebRTC. Reported by ngrunbaum on 2026-04-15
[N/A][502814490] Medium CVE-2026-87590: Improper input validation in Passwords. Reported by Google on 2026-04-15
[N/A][502986244] Medium CVE-2026-87580: Incorrect authorization in WebAppInstalls. Reported by Google on 2026-04-15
[N/A][503736006] Medium CVE-2026-87482: Cleartext transmission of sensitive data in HttpsUpgrades. Reported by Google on 2026-04-17
[N/A][504670493] Medium CVE-2026-87497: Uninitialized resource in Codecs. Reported by Google on 2026-04-20
[N/A][504690157] Medium CVE-2026-87579: Buffer overflow in WebRTC. Reported by Google on 2026-04-20
[N/A][506385755] Medium CVE-2026-87576: Uninitialized resource in GPU. Reported by Google on 2026-04-25
[N/A][506390077] Medium CVE-2026-87476: Incorrect authorization in Loader. Reported by Google on 2026-04-25
[N/A][507225626] Medium CVE-2026-87475: Missing authorization in Omnibox. Reported by Google on 2026-04-28
[N/A][511754574] Medium CVE-2026-87436: Incomplete cleanup in Browser. Reported by Google on 2026-05-10
[N/A][511772271] Medium CVE-2026-87479: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-10
[N/A][511773417] Medium CVE-2026-87513: Missing authorization in ControlledFrame. Reported by Google on 2026-05-10
[N/A][511820041] Medium CVE-2026-87432: Incorrect authorization in Navigation. Reported by Google on 2026-05-10
[N/A][511824746] Medium CVE-2026-87560: Missing authorization in Browser. Reported by Google on 2026-05-10
[N/A][512986143] Medium CVE-2026-87521: Information leak in WebMCP. Reported by Google on 2026-05-13
[N/A][513003268] Medium CVE-2026-87539: Observable discrepancy in Network. Reported by Google on 2026-05-14
[N/A][513048243] Medium CVE-2026-87648: Use after free in ANGLE. Reported by Google on 2026-05-14
[N/A][513134173] Medium CVE-2026-87534: Missing authorization in WebView. Reported by Google on 2026-05-14
[N/A][513135531] Medium CVE-2026-87562: Incorrect reference resolution in Accessibility. Reported by Google on 2026-05-14
[N/A][513192482] Medium CVE-2026-87556: Missing authorization in Browser. Reported by Google on 2026-05-14
[N/A][513346220] Medium CVE-2026-87508: Incorrect authorization in Loader. Reported by Google on 2026-05-14
[N/A][513416699] Medium CVE-2026-87643: Integer overflow in GPU. Reported by Google on 2026-05-15
[N/A][513438970] Medium CVE-2026-87573: Improper input validation in Network. Reported by Google on 2026-05-15
[N/A][513495219] Medium CVE-2026-87548: Improper state validation in Installer. Reported by Google on 2026-05-15
[N/A][513509804] Medium CVE-2026-87501: UI misrepresentation in Passwords. Reported by Google on 2026-05-15
[N/A][513524705] Medium CVE-2026-87452: Incorrect authorization in GPU. Reported by Google on 2026-05-15
[N/A][513608513] Medium CVE-2026-87516: Observable discrepancy in Navigation. Reported by Google on 2026-05-15
[N/A][513702096] Medium CVE-2026-87599: Improper input validation in Interstitials. Reported by Google on 2026-05-16
[N/A][514009699] Medium CVE-2026-87507: UI misrepresentation in Downloads. Reported by Google on 2026-05-17
[N/A][514011926] Medium CVE-2026-87559: UI misrepresentation in UI. Reported by Google on 2026-05-17
[N/A][514016678] Medium CVE-2026-87472: Improper input validation in FedCM. Reported by Google on 2026-05-17
[N/A][514017067] Medium CVE-2026-87486: Clickjacking in TrustedWebActivities. Reported by Google on 2026-05-17
[N/A][514023309] Medium CVE-2026-87655: Clickjacking in Downloads. Reported by Google on 2026-05-17
[N/A][514041087] Medium CVE-2026-87462: UI misrepresentation in FedCM. Reported by Google on 2026-05-17
[N/A][514055890] Medium CVE-2026-87649: UI misrepresentation in Downloads. Reported by Google on 2026-05-17
[N/A][514056835] Medium CVE-2026-87445: UI misrepresentation in Session. Reported by Google on 2026-05-17
[N/A][514069596] Medium CVE-2026-87567: UI misrepresentation in UrlFormatting. Reported by Google on 2026-05-17
[N/A][514074827] Medium CVE-2026-87496: UI misrepresentation in Browser. Reported by Google on 2026-05-17
[N/A][514556469] Medium CVE-2026-87441: Missing authorization in Downloads. Reported by Google on 2026-05-19
[N/A][516534546] Medium CVE-2026-87549: Incomplete cleanup in Downloads. Reported by Google on 2026-05-25
[N/A][517072005] Medium CVE-2026-87458: UI misrepresentation in Geometry. Reported by Google on 2026-05-27
[N/A][517092658] Medium CVE-2026-87574: Information leak in ServiceWorker. Reported by Google on 2026-05-27
[N/A][517122234] Medium CVE-2026-87495: Information leak in Scroll. Reported by Google on 2026-05-27
[N/A][517156678] Medium CVE-2026-87541: Information leak in Navigation. Reported by Google on 2026-05-27
[N/A][517178299] Medium CVE-2026-87451: Information leak in Downloads. Reported by Google on 2026-05-27
[N/A][517215407] Medium CVE-2026-87570: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-27
[N/A][517337579] Medium CVE-2026-87555: Uninitialized resource in GPU. Reported by Google on 2026-05-28
[N/A][517339356] Medium CVE-2026-87600: Improper input validation in Safebrowsing. Reported by Google on 2026-05-28
[N/A][517369256] Medium CVE-2026-87532: Improper state validation in Safebrowsing. Reported by Google on 2026-05-28
[N/A][517415433] Medium CVE-2026-87439: Information leak in ServiceWorker. Reported by Google on 2026-05-28
[N/A][517432155] Medium CVE-2026-87450: Incorrect authorization in Permissions. Reported by Google on 2026-05-28
[N/A][517597701] Medium CVE-2026-87505: Incorrect authorization in FileSystem. Reported by Google on 2026-05-28
[N/A][517602176] Medium CVE-2026-87622: Missing authorization in FedCM. Reported by Google on 2026-05-28
[N/A][517721914] Medium CVE-2026-87540: Incorrect authorization in Isolated. Reported by Google on 2026-05-29
[N/A][517732336] Medium CVE-2026-87594: Incorrect authorization in DataTransfer. Reported by Google on 2026-05-29
[N/A][517917560] Medium CVE-2026-87518: Observable discrepancy in Safebrowsing. Reported by Google on 2026-05-29
[N/A][518002426] Medium CVE-2026-87589: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-29
[N/A][518039263] Medium CVE-2026-87484: UI misrepresentation in Geometry. Reported by Google on 2026-05-29
[N/A][518081914] Medium CVE-2026-87530: Uncontrolled search path element in CredentialProvider. Reported by Google on 2026-05-30
[N/A][518082852] Medium CVE-2026-87550: Improper encoding or escaping of output in CSS. Reported by Google on 2026-05-30
[N/A][520161438] Medium CVE-2026-87494: Use after free in Browser. Reported by Google on 2026-06-05
[N/A][520201931] Medium CVE-2026-87483: Incorrect authorization in Browser. Reported by Google on 2026-06-05
[N/A][520389619] Medium CVE-2026-87454: Information leak in Enterprise. Reported by Google on 2026-06-05
[N/A][520469117] Medium CVE-2026-87616: Improper initialization in Views. Reported by Google on 2026-06-05
[N/A][520572550] Medium CVE-2026-87535: Information loss or omission in Safebrowsing. Reported by Google on 2026-06-06
[N/A][521616899] Medium CVE-2026-87644: Incorrect authorization in Views. Reported by Google on 2026-06-09
[N/A][521620916] Medium CVE-2026-87533: Use after free in DevTools. Reported by Google on 2026-06-09
[N/A][522304737] Medium CVE-2026-87635: UI misrepresentation in Payments. Reported by Google on 2026-06-10
[N/A][523091391] Medium CVE-2026-87641: Race condition in Browser. Reported by Google on 2026-06-12
[N/A][523313374] Medium CVE-2026-87431: Missing authorization in Extensions. Reported by Microsoft Edge on 2026-06-12
[N/A][523741272] Medium CVE-2026-87493: Missing authorization in FileSystem. Reported by Google on 2026-06-14
[N/A][532921336] Medium CVE-2026-87625: Use after free in V8. Reported by Google on 2026-07-09
[N/A][532931962] Medium CVE-2026-87468: Incorrect authorization in Isolated. Reported by Google on 2026-07-09
[N/A][532952073] Medium CVE-2026-87563: Origin validation error in Paint. Reported by Google on 2026-07-09
[N/A][532957878] Medium CVE-2026-87510: Improper input validation in FileAPI. Reported by Google on 2026-07-09
[N/A][533070113] Medium CVE-2026-87435: Information leak in ControlledFrame. Reported by Google on 2026-07-09
[N/A][533597592] Medium CVE-2026-87531: Information leak in CORS. Reported by Google on 2026-07-11
[N/A][534863145] Medium CVE-2026-87637: Use after free in Extensions. Reported by Google on 2026-07-14
[N/A][536423794] Medium CVE-2026-87529: Numeric truncation error in Media. Reported by Google on 2026-07-19
[N/A][536446354] Medium CVE-2026-87470: Improper quantity validation in Tint. Reported by Google on 2026-07-19
[N/A][536598187] Medium CVE-2026-87586: Out of bounds read in ANGLE. Reported by Google on 2026-07-19
[N/A][537466493] Medium CVE-2026-87584: Incorrect authorization in WebUI. Reported by Google on 2026-07-21
[TBD][538197156] Medium CVE-2026-87632: Cross-site scripting in SanitizerAPI. Reported by Eli Ainhorn on 2026-07-24
[N/A][539569491] Medium CVE-2026-87528: Type confusion in Rust. Reported by marcobartoli on 2026-07-27
[N/A][540015493] Medium CVE-2026-87623: Observable discrepancy in DOM. Reported by Google on 2026-07-28
[N/A][540021850] Medium CVE-2026-87566: Observable discrepancy in Layout. Reported by Google on 2026-07-28
[N/A][540024134] Medium CVE-2026-87638: Out of bounds write in Media. Reported by Google on 2026-07-28
[N/A][542565481] Medium CVE-2026-87455: Use after free in Aura. Reported by Microsoft on 2026-08-04
[TBD][543938457] Medium CVE-2026-87591: Incorrect authorization in Extensions. Reported by antoniosmr02 on 2026-08-07
[N/A][544484669] Medium CVE-2026-87526: Use after free in Passwords. Reported by shab on 2026-08-10
[N/A][547322272] Medium CVE-2026-87609: Use after free in Sharing. Reported by Google on 2026-08-16
[TBD][547592631] Medium CVE-2026-87610: Incorrect authorization in Omnibox. Reported by Arni Hardarson (Neonix Security) on 2026-08-17
[N/A][553155590] Medium CVE-2026-87626: Incorrect authorization in DeviceBoundSessionCredentials. Reported by Google on 2026-08-26
[$1,500][490773579] Low CVE-2026-87629: Incorrect authorization in Sources. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab on 2026-03-08
[$500][40058710] Low CVE-2026-87653: UI misrepresentation in FullScreen. Reported by Lijo A.T on 2022-02-07
[N/A][349994197] Low CVE-2026-87634: Use after free in WebPackaging. Reported by Google on 2024-06-28
[N/A][497025031] Low CVE-2026-87429: Missing authorization in ServiceWorker. Reported by Google on 2026-03-27
[N/A][497203958] Low CVE-2026-87618: Incorrect reference resolution in Storage. Reported by Google on 2026-03-28
[N/A][497359396] Low CVE-2026-87614: Incorrect authorization in ServiceWorker. Reported by Google on 2026-03-29
[N/A][497433347] Low CVE-2026-87619: Observable discrepancy in Prefetch. Reported by Google on 2026-03-29
[N/A][499217288] Low CVE-2026-87561: Incorrect authorization in Web Authentication. Reported by Google on 2026-04-03
[N/A][499218516] Low CVE-2026-87598: Incorrect authorization in ServiceWorker. Reported by Google on 2026-04-03
[N/A][501763003] Low CVE-2026-87519: Incorrect authorization in Safebrowsing. Reported by Google on 2026-04-11
[N/A][502452118] Low CVE-2026-87543: Missing authorization in Core. Reported by Google on 2026-04-14
[N/A][507219126] Low CVE-2026-87522: Missing authorization in WebView. Reported by Google on 2026-04-28
[N/A][513143955] Low CVE-2026-87568: Improper input validation in Chromium. Reported by Google on 2026-05-14
[N/A][513245072] Low CVE-2026-87656: Improper state validation in Safebrowsing. Reported by Google on 2026-05-14
[N/A][513395384] Low CVE-2026-87511: Missing authorization in DevTools. Reported by Google on 2026-05-15
[N/A][513473551] Low CVE-2026-87627: Interpretation conflict in Safebrowsing. Reported by Google on 2026-05-15
[N/A][513726466] Low CVE-2026-87595: Server-side request forgery in Mobile. Reported by Google on 2026-05-16
[N/A][513947572] Low CVE-2026-87592: Out of bounds read in Tint. Reported by Google on 2026-05-17
[N/A][514489101] Low CVE-2026-87620: Observable discrepancy in SVG. Reported by Google on 2026-05-19
[N/A][515426792] Low CVE-2026-87502: Confused deputy in Fullscreen. Reported by Google on 2026-05-21
[N/A][516965176] Low CVE-2026-87448: Use after free in DevTools. Reported by Google on 2026-05-27
[N/A][517219513] Low CVE-2026-87459: Observable discrepancy in Select. Reported by Google on 2026-05-27
[N/A][517776674] Low CVE-2026-87463: Incorrect authorization in Certificate. Reported by Google on 2026-05-29
[N/A][517926950] Low CVE-2026-87546: Incorrect type conversion or cast in Safebrowsing. Reported by Google on 2026-05-29
[N/A][522399466] Low CVE-2026-87538: Clickjacking in Input. Reported by Google on 2026-06-10
[N/A][523243507] Low CVE-2026-87545: Information leak in Mobile. Reported by Google on 2026-06-12
[N/A][523442920] Low CVE-2026-87617: Use after free in DevTools. Reported by Google on 2026-06-13
[N/A][532933816] Low CVE-2026-87523: Race condition in DataTransfer. Reported by Google on 2026-07-09
[N/A][532968511] Low CVE-2026-87565: Information leak in Passwords. Reported by Google on 2026-07-09
[N/A][533018632] Low CVE-2026-87597: UI misrepresentation in CustomTabs. Reported by Google on 2026-07-09
[N/A][533044125] Low CVE-2026-87624: UI misrepresentation in Passwords. Reported by Google on 2026-07-09
[N/A][533084499] Low CVE-2026-87605: Missing authorization in Contacts. Reported by Google on 2026-07-09
[N/A][533112829] Low CVE-2026-87490: Information leak in Transactions Platform. Reported by Google on 2026-07-09
[N/A][533116484] Low CVE-2026-87583: UI misrepresentation in Passwords. Reported by Google on 2026-07-09
[N/A][535718578] Low CVE-2026-87509: Incorrect authorization in Updater. Reported by Google on 2026-07-16
[N/A][537101736] Low CVE-2026-87473: Incorrect authorization in FileHandling. Reported by Google on 2026-07-21
[N/A][537470182] Low CVE-2026-87461: Information leak in Core. Reported by Google on 2026-07-21
[N/A][537476242] Low CVE-2026-87631: Missing authorization in DOM. Reported by Google on 2026-07-21
[TBD][538715523] Low CVE-2026-87469: Improper input validation in Extensions. Reported by Jeong Woo Lee (@eclipse07077) on 2026-07-24
[N/A][539453394] Low CVE-2026-87489: Memory corruption in V8. Reported by Google on 2026-07-27
[N/A][540013886] Low CVE-2026-87575: Incorrect authorization in Loader. Reported by Google on 2026-07-28
[N/A][540046516] Low CVE-2026-87571: Improper certificate validation in Loader. Reported by Google on 2026-07-28
[N/A][540059211] Low CVE-2026-87477: Information leak in Core. Reported by Google on 2026-07-28
[N/A][540070236] Low CVE-2026-87551: Improper certificate validation in CORS. Reported by Google on 2026-07-28
[N/A][540072282] Low CVE-2026-87608: Improper certificate validation in FedCM. Reported by Google on 2026-07-28
[N/A][540082621] Low CVE-2026-87437: Information leak in Frames. Reported by Google on 2026-07-28
[TBD][541546782] Low CVE-2026-87602: Out of bounds read in ANGLE. Reported by Hyeongeun Ji of JeroScope on 2026-08-01
[TBD][541604100] Low CVE-2026-87601: Race condition in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-01
[TBD][542355360] Low CVE-2026-87544: Incorrect authorization in Extensions. Reported by antoniosmr02 on 2026-08-04
[TBD][542449805] Low CVE-2026-87430: Buffer overflow in WebRTC. Reported by k-kyuno on 2026-08-04
[N/A][553252820] Low CVE-2026-87593: Information leak in Editing. Reported by Google on 2026-08-27

Google is aware that an exploit for CVE-2026-87491 exists in the wild.
 
Google Chrome 153.0.8010.47/.48 Stable Channel Update for Desktop
This update includes 42 security fixes. Please see the Chrome Security Page for more information.

[N/A][556870863] Critical CVE-2026-91726: Out of bounds read in WebGL. Reported by Google on 2026-09-03
[TBD][557320614] Critical CVE-2026-91721: Use after free in Internals. Reported by xinyang on 2026-09-04
[TBD][558456602] Critical CVE-2026-91749: Use after free in Workers. Reported by WinD39 - Huynh Dinh Vu on 2026-09-08
[$1,500][552283275] High CVE-2026-91724: Use after free in Input. Reported by Hafiizh on 2026-08-25
[$1,000][556715288] High CVE-2026-91728: Integer overflow in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-09-03
[N/A][516780835] High CVE-2026-91734: Incorrect authorization in Core. Reported by Google on 2026-05-26
[N/A][516893912] High CVE-2026-91727: Incorrect reference resolution in Extensions. Reported by Google on 2026-05-26
[N/A][516947138] High CVE-2026-91743: Race condition in Core. Reported by Google on 2026-05-27
[N/A][520019273] High CVE-2026-91744: Race condition in PlatformIntegration. Reported by Google on 2026-06-04
[N/A][521486621] High CVE-2026-91712: Race condition in Extensions. Reported by Google on 2026-06-08
[N/A][521559611] High CVE-2026-91748: Race condition in Extensions. Reported by Google on 2026-06-09
[N/A][523470135] High CVE-2026-91720: Uninitialized resource in ANGLE. Reported by Google on 2026-06-13
[N/A][523554372] High CVE-2026-91731: Type confusion in Compositing. Reported by Google on 2026-06-13
[N/A][540016074] High CVE-2026-91747: Use after free in Skia. Reported by Google on 2026-07-28
[N/A][540021213] High CVE-2026-91733: Improper state validation in Skia. Reported by Google on 2026-07-28
[TBD][546413288] High CVE-2026-91741: Type confusion in CacheStorage. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-14
[TBD][547815507] High CVE-2026-91709: Type confusion in ServiceWorker. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17
[TBD][549225472] High CVE-2026-91717: Missing authorization in Android. Reported by jodyritonga on 2026-08-20
[N/A][552416113] High CVE-2026-91735: Incorrect authorization in WebUI. Reported by Google on 2026-08-25
[N/A][553115724] High CVE-2026-91708: Race condition in Network. Reported by Google on 2026-08-26
[N/A][553121008] High CVE-2026-91736: Use after free in DOM. Reported by Google on 2026-08-26
[N/A][553122373] High CVE-2026-91740: Uninitialized resource in Skia. Reported by Google on 2026-08-26
[N/A][553132148] High CVE-2026-91710: Use after free in WebAppInstalls. Reported by Google on 2026-08-26
[N/A][553133215] High CVE-2026-91718: Use after free in Core. Reported by Google on 2026-08-26
[N/A][554558368] High CVE-2026-91716: Use after free in Auth. Reported by Google on 2026-08-29
[N/A][556260782] High CVE-2026-91746: Integer overflow in Compositing. Reported by Google on 2026-09-02
[TBD][557206809] High CVE-2026-91729: Use after free in DigitalCredentials. Reported by sean geofrey on 2026-09-04
[TBD][558036280] High CVE-2026-91737: Use after free in PDF. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) on 2026-09-06
[TBD][558342353] High CVE-2026-91711: Out of bounds write in ServiceWorker. Reported by Cristian Di Nicola (@crih.exe) on 2026-09-07
[TBD][558367547] High CVE-2026-91715: Type confusion in ServiceWorker. Reported by Cristian Di Nicola (@crih.exe) on 2026-09-07
[N/A][558734727] High CVE-2026-91745: Use after free in V8. Reported by Google on 2026-09-08
[TBD][474131239] Medium CVE-2026-91723: Race condition in WebAppInstalls. Reported by Luan Herrera (@lbherrera_) on 2026-01-07
[TBD][511062248] Medium CVE-2026-91732: Missing authorization in AppManifest. Reported by pakhunov.anton.n on 2026-05-08
[N/A][513858387] Medium CVE-2026-91742: Confused deputy in PriceTracking. Reported by Google on 2026-05-16
[N/A][517710554] Medium CVE-2026-91714: Observable discrepancy in Fonts. Reported by Google on 2026-05-29
[N/A][518032534] Medium CVE-2026-91725: Observable discrepancy in CSS. Reported by Google on 2026-05-29
[N/A][521951328] Medium CVE-2026-91739: Missing authorization in Transactions Platform. Reported by Google on 2026-06-09
[N/A][523715133] Medium CVE-2026-91713: Missing authorization in Browser. Reported by Google on 2026-06-14
[N/A][536450979] Medium CVE-2026-91738: Improper input validation in ANGLE. Reported by Google on 2026-07-19
[TBD][543640868] Medium CVE-2026-91730: Incomplete cleanup in GetUserMedia. Reported by Keita Sode and Daisuke Hatakeyama (SYZD Research) on 2026-08-07
[TBD][554953456] Medium CVE-2026-91722: Use after free in Input. Reported by TIENPA on 2026-08-31
[TBD][542115030] Low CVE-2026-91719: Code injection in XML. Reported by Zabith Mohammed (@nmzabith) on 2026-08-03
 
Google Chrome 153.0.8010.52/.53 Stable Channel Update for Desktop
This update includes 16 security fixes. Please see the Chrome Security Page for more information.

[TBD][500417361] Critical CVE-2026-93374: Use after free in Dawn. Reported by Florian Schweitzer on 2026-04-08
[N/A][548085797] Critical CVE-2026-93372: Buffer overflow in WebGL. Reported by Google on 2026-08-17
[$3,000][550839154] High CVE-2026-93375: Incorrect reference resolution in Tracing. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-08-22
[TBD][541707261] High CVE-2026-93382: Use after free in PDFium. Reported by WinD39 - Huynh Dinh Vu on 2026-08-02
[N/A][553130676] High CVE-2026-93387: Improper state validation in Skia. Reported by Google on 2026-08-26
[N/A][553132214] High CVE-2026-93373: Use after free in Extensions. Reported by Google on 2026-08-26
[TBD][556853443] High CVE-2026-93381: Buffer overflow in PDFium. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) on 2026-09-03
[TBD][560039872] High CVE-2026-93379: Incorrect authorization in ORB. Reported by OGINOME Tomohito on 2026-09-11
[N/A][560121552] High CVE-2026-93377: Type confusion in V8. Reported by Google on 2026-09-11
[N/A][498411599] Medium CVE-2026-93380: Race condition in FileSystem. Reported by Google on 2026-04-01
[N/A][511832293] Medium CVE-2026-93384: Server-side request forgery in Omnibox. Reported by Google on 2026-05-10
[N/A][515493668] Medium CVE-2026-93383: Information leak in Permissions. Reported by Google on 2026-05-22
[N/A][520521197] Medium CVE-2026-93376: Out of bounds read in DataTransfer. Reported by Google on 2026-06-05
[N/A][540051167] Medium CVE-2026-93378: Missing authorization in Storage. Reported by Google on 2026-07-28
[N/A][553136980] Medium CVE-2026-93385: Information leak in Paint. Reported by Google on 2026-08-26
[N/A][513996595] Low CVE-2026-93386: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-17
 
Stable Channel Update for Desktop
Tuesday, September 22, 2026
Chrome 154.0.8037.57 (Linux) 154.0.8037.57/.58 Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 154.

Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 108 security fixes. Please see the Chrome Security Page for more information.
Chrome Releases
 
Google Chrome 154.0.8037.92/.93 Stable Channel Update for Desktop
This update includes 32 security fixes. Please see the Chrome Security Page for more information.

[TBD][551673541] Critical CVE-2026-102331: Buffer overflow in ANGLE. Reported by @mfx on 2026-08-24
[N/A][517312707] High CVE-2026-102317: Improper privilege management in Mojo. Reported by Google on 2026-05-28
[TBD][551668264] High CVE-2026-102312: UI misrepresentation in Omnibox. Reported by jodyritonga on 2026-08-24
[N/A][556789073] High CVE-2026-102313: Uninitialized resource in ANGLE. Reported by Google on 2026-09-03
[TBD][556908674] High CVE-2026-102299: Type confusion in V8. Reported by Andrew Boni on 2026-09-04
[N/A][556926296] High CVE-2026-102306: Use after free in Bluetooth. Reported by Google on 2026-09-04
[N/A][556959073] High CVE-2026-102307: Uninitialized resource in Dawn. Reported by Google on 2026-09-04
[TBD][559266114] High CVE-2026-102323: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-10
[N/A][559727039] High CVE-2026-102303: Uninitialized resource in GPU. Reported by Google on 2026-09-10
[N/A][559737160] High CVE-2026-102311: Uninitialized resource in GPU. Reported by Google on 2026-09-10
[TBD][560062638] High CVE-2026-102300: Uninitialized resource in WebGPU. Reported by Arni Hardarson (Neonix Security) on 2026-09-11
[TBD][560233248] High CVE-2026-102326: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-11
[TBD][560238698] High CVE-2026-102316: Use after free in Views. Reported by Xinyang Ge on 2026-09-11
[TBD][560251736] High CVE-2026-102304: Use after free in Passwords. Reported by Xinyang Ge on 2026-09-11
[TBD][560536732] High CVE-2026-102328: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12
[TBD][560867085] High CVE-2026-102309: Use after free in FullScreen. Reported by sean geofrey on 2026-09-13
[N/A][561994362] High CVE-2026-102325: Uninitialized resource in Skia. Reported by Google on 2026-09-15
[N/A][561997480] High CVE-2026-102308: Use after free in Views. Reported by Google on 2026-09-15
[N/A][562004351] High CVE-2026-102301: Out of bounds write in GPU. Reported by Google on 2026-09-15
[N/A][562042411] High CVE-2026-102319: Uninitialized resource in GPU. Reported by Google on 2026-09-15
[TBD][562174487] High CVE-2026-102324: Use after free in PictureInPicture. Reported by Blockian Creator of Kritt and Open-Kritt on 2026-09-15
[N/A][562279351] High CVE-2026-102318: Out of bounds read in WebGL. Reported by Google on 2026-09-16
[TBD][563297615] High CVE-2026-102329: Cross-site scripting in WebUI. Reported by chipsec on 2026-09-18
[N/A][563351482] High CVE-2026-102315: Uninitialized resource in Media. Reported by Google on 2026-09-18
[N/A][563716534] High CVE-2026-102302: Buffer overflow in V8. Reported by Google on 2026-09-19
[TBD][565328105] High CVE-2026-102321: Type confusion in V8. Reported by Taisic Yun (@taisic_) of Theori, with Xint on 2026-09-23
[TBD][554038924] Medium CVE-2026-102320: Missing authorization in CORS. Reported by Anonymous on 2026-08-28
[$1,000][477726837] Low CVE-2026-102310: Missing authorization in Payments. Reported by Autodidact on 2026-01-22
[N/A][496212975] Low CVE-2026-102327: Incorrect authorization in WebView. Reported by Google on 2026-03-25
[N/A][498793976] Low CVE-2026-102330: Incorrect authorization in SiteIsolation. Reported by Google on 2026-04-02
[N/A][514059780] Low CVE-2026-102314: UI misrepresentation in TabStrip. Reported by Google on 2026-05-17
[N/A][533021953] Low CVE-2026-102305: UI misrepresentation in SignIn. Reported by Google on 2026-07-09
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top