❌

Normale weergave

Early Stable Update for Desktop

26 Augustus 2026 om 19:14

The Stable channel has been updated to 153.0.8010.12/.13 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Stable Channel Update for Desktop

25 Augustus 2026 om 21:19

The Chrome team is delighted to announce the promotion of Chrome 152 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.

Chrome 152.0.7977.64 (Linux)Β 152.0.7977.64/.65Β Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 152.


Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 327 security fixes. Please see the Chrome Security Page for more information.


[$25,000][496807874] Critical CVE-2026-79282: Use after free in ANGLE. Reported by Goodluck on 2026-03-27

[N/A][516427761] Critical CVE-2026-79290: Use after free in Aura. Reported by Google on 2026-05-25

[N/A][516764384] Critical CVE-2026-79054: Use after free in Chromecast. Reported by Google on 2026-05-26

[N/A][516777082] Critical CVE-2026-79121: Improper input validation in Chromecast. Reported by Google on 2026-05-26

[N/A][516988476] Critical CVE-2026-79224: Use after free in Chromecast. Reported by Google on 2026-05-27

[N/A][517518019] Critical CVE-2026-79052: Use after free in Aura. Reported by Google on 2026-05-28

[N/A][518006007] Critical CVE-2026-79150: Use after free in Views. Reported by Google on 2026-05-29

[N/A][522082472] Critical CVE-2026-78935: Use of uninitialized variable in Mobile. Reported by Google on 2026-06-10

[N/A][523704817] Critical CVE-2026-79012: Use after free in Safebrowsing. Reported by Google on 2026-06-13

[N/A][532921800] Critical CVE-2026-79200: Use after free in Aura. Reported by Google on 2026-07-09

[$1,000][532617619] High CVE-2026-78989: Out of bounds read in ANGLE. Reported by Đặng Thế Tuyến on 2026-07-09

[$500][508638064] High CVE-2026-79069: Memory corruption in Tint. Reported by andryskowski.michal on 2026-05-01

[N/A][498885920] High CVE-2026-79175: Type confusion in Accessibility. Reported by Google on 2026-04-02

[N/A][500311587] High CVE-2026-79218: Incorrect authorization in Sandbox. Reported by Google on 2026-04-07

[N/A][501892500] High CVE-2026-79195: Use after free in Script. Reported by Google on 2026-04-12

[N/A][513261751] High CVE-2026-78939: Use after free in Chromecast. Reported by Google on 2026-05-14

[N/A][515470739] High CVE-2026-79194: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][515473074] High CVE-2026-79247: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][516947491] High CVE-2026-79219: Use after free in Bluetooth. Reported by Google on 2026-05-27

[N/A][517515945] High CVE-2026-79047: Use after free in Views. Reported by Google on 2026-05-28

[N/A][517519352] High CVE-2026-79292: Integer overflow in Chromecast. Reported by Google on 2026-05-28

[N/A][517527943] High CVE-2026-78986: Uninitialized resource in GPU. Reported by Google on 2026-05-28

[N/A][517548647] High CVE-2026-79039: Use after free in Mobile. Reported by Google on 2026-05-28

[N/A][517550232] High CVE-2026-78934: Race condition in ReadAloud. Reported by Google on 2026-05-28

[N/A][517736936] High CVE-2026-79011: UI misrepresentation in Browser. Reported by Google on 2026-05-29

[N/A][517742721] High CVE-2026-78911: Incorrect authorization in USB. Reported by Google on 2026-05-29

[N/A][517959443] High CVE-2026-79257: Use after free in Views. Reported by Google on 2026-05-29

[N/A][521285077] High CVE-2026-79202: Use after free in Chromecast. Reported by Google on 2026-06-08

[N/A][521502218] High CVE-2026-79212: Missing authorization in Passwords. Reported by Google on 2026-06-08

[N/A][521942358] High CVE-2026-79183: Use after free in Accessibility. Reported by Google on 2026-06-09

[N/A][522294538] High CVE-2026-79155: Race condition in FileSystem. Reported by Google on 2026-06-10

[N/A][523095011] High CVE-2026-79093: Incorrect authorization in Paint. Reported by Google on 2026-06-12

[N/A][523266585] High CVE-2026-79019: Out of bounds write in ANGLE. Reported by Google on 2026-06-12

[N/A][523296105] High CVE-2026-79187: Use after free in WebRTC. Reported by Google on 2026-06-12

[N/A][523714535] High CVE-2026-79288: Improper input validation in Autofill. Reported by Google on 2026-06-14

[N/A][523717796] High CVE-2026-79130: Buffer overflow in ANGLE. Reported by Google on 2026-06-14

[N/A][523723064] High CVE-2026-78965: Uninitialized resource in ANGLE. Reported by Google on 2026-06-14

[N/A][523738212] High CVE-2026-79117: Race condition in WebAppInstalls. Reported by Google on 2026-06-14

[N/A][524698525] High CVE-2026-79082: Incorrect authorization in Transactions Platform. Reported by Google on 2026-06-16

[N/A][525683797] High CVE-2026-79111: Improper input validation in Dawn. Reported by Google on 2026-06-19

[N/A][528397177] High CVE-2026-79072: Improper state validation in Performance. Reported by Google on 2026-06-27

[N/A][529509587] High CVE-2026-79142: Buffer overflow in ANGLE. Reported by Google on 2026-06-30

[N/A][529991907] High CVE-2026-78948: Buffer overflow in WebGL. Reported by Google on 2026-07-01

[N/A][532904047] High CVE-2026-78908: Information leak in Canvas. Reported by Google on 2026-07-09

[N/A][532914190] High CVE-2026-78895: Information leak in Paint. Reported by Google on 2026-07-09

[N/A][532988552] High CVE-2026-79043: Out of bounds write in ANGLE. Reported by Google on 2026-07-09

[N/A][534468209] High CVE-2026-79235: Use after free in WebGL. Reported by Google on 2026-07-13

[N/A][534591074] High CVE-2026-79232: Use after free in Aura. Reported by Google on 2026-07-14

[N/A][535379043] High CVE-2026-79118: Uninitialized resource in ANGLE. Reported by Google on 2026-07-16

[TBD][535876894] High CVE-2026-79174: Incorrect authorization in Extensions. Reported by η« ι±Όε“₯@aipyaipy.com on 2026-07-17

[N/A][536428615] High CVE-2026-78900: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536444272] High CVE-2026-79188: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536505721] High CVE-2026-79189: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536531630] High CVE-2026-79048: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536532605] High CVE-2026-79240: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536568319] High CVE-2026-79014: Race condition in Autofill. Reported by Google on 2026-07-19

[N/A][536606137] High CVE-2026-79198: Use after free in Platform. Reported by Google on 2026-07-19

[N/A][536626343] High CVE-2026-79131: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536636648] High CVE-2026-79149: Use after free in ANGLE. Reported by Google on 2026-07-19

[N/A][536659904] High CVE-2026-79275: Use after free in ANGLE. Reported by Google on 2026-07-20

[N/A][536681676] High CVE-2026-79138: Out of bounds write in ANGLE. Reported by Google on 2026-07-20

[N/A][537109028] High CVE-2026-79026: Use after free in Extensions. Reported by Google on 2026-07-21

[TBD][537233963] High CVE-2026-79027: Use after free in WebRTC. Reported by Mozilla on 2026-07-21

[N/A][537835609] High CVE-2026-78904: Type confusion in ANGLE. Reported by Google on 2026-07-22

[TBD][540430406] High CVE-2026-78899: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-07-29

[N/A][540870921] High CVE-2026-78954: Incorrect authorization in Extensions. Reported by Google on 2026-07-30

[TBD][543707066] High CVE-2026-79274: Information leak in GPU. Reported by weihengqiuu on 2026-08-07

[TBD][545767601] High CVE-2026-78938: Type confusion in V8. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-08-12

[TBD][545820931] High CVE-2026-78952: Out of bounds write in Crashpad. Reported by Brendan Dolan-Gavitt, XBOW on 2026-08-13

[TBD][546670199] High CVE-2026-79236: Type confusion in V8. Reported by Zhenpeng (Leo) Lin on 2026-08-14

[TBD][548340637] High CVE-2026-79078: Use after free in FedCM. Reported by m0omo0d on 2026-08-18

[$8,000][495021566] Medium CVE-2026-79209: Type confusion in Animation. Reported by ochko on 2026-03-22

[$2,000][40057398] Medium CVE-2026-79030: Observable discrepancy in Autofill. Reported by Young Min Kim (@ylemkimon), CompSec Lab at Seoul National

University on 2021-09-25

[$1,000][536913431] Medium CVE-2026-79216: Buffer overflow in Blink. Reported by Found by XBOW and triaged by AndrΓ©s Luksenberg on 2026-07-20

[N/A][495579602] Medium CVE-2026-79007: Uninitialized resource in GPU. Reported by Google on 2026-03-24

[N/A][495998981] Medium CVE-2026-78893: Information leak in QUIC. Reported by Google on 2026-03-25

[N/A][496195129] Medium CVE-2026-79222: Incorrect authorization in CustomTabs. Reported by Google on 2026-03-25

[N/A][496292729] Medium CVE-2026-79071: Race condition in GPU. Reported by Google on 2026-03-25

[N/A][496395158] Medium CVE-2026-79076: Improper input validation in Sync. Reported by Google on 2026-03-26

[N/A][496401361] Medium CVE-2026-79088: Incorrect authorization in FileSystem. Reported by Google on 2026-03-26

[N/A][497017869] Medium CVE-2026-79104: Missing authorization in Sensor. Reported by Google on 2026-03-27

[N/A][497095313] Medium CVE-2026-79044: Missing authorization in WebAppInstalls. Reported by Google on 2026-03-28

[N/A][497205529] Medium CVE-2026-78958: Uninitialized resource in Skia. Reported by Google on 2026-03-28

[N/A][497269030] Medium CVE-2026-78961: Incorrect authorization in Core. Reported by Google on 2026-03-28

[N/A][497338168] Medium CVE-2026-79262: Incorrect authorization in Network. Reported by Google on 2026-03-29

[N/A][497456156] Medium CVE-2026-79106: Improper input validation in Input. Reported by Google on 2026-03-29

[N/A][497538341] Medium CVE-2026-79176: UI misrepresentation in Extensions. Reported by Google on 2026-03-29

[N/A][497637694] Medium CVE-2026-78966: Externally controlled reference in QUIC. Reported by Google on 2026-03-30

[N/A][497646947] Medium CVE-2026-79186: Incorrect authorization in Network. Reported by Google on 2026-03-30

[N/A][497839983] Medium CVE-2026-79267: Race condition in Workers. Reported by Google on 2026-03-30

[N/A][497854976] Medium CVE-2026-79016: Observable discrepancy in SVG. Reported by Google on 2026-03-30

[N/A][497869284] Medium CVE-2026-79010: Operation on a resource after expiration or release in Network. Reported by Google on 2026-03-30

[N/A][497940451] Medium CVE-2026-79286: Missing authorization in CustomTabs. Reported by Google on 2026-03-30

[N/A][497948894] Medium CVE-2026-78945: Use after free in Views. Reported by Google on 2026-03-30

[N/A][497957278] Medium CVE-2026-78999: Improper privilege management in Navigation. Reported by Google on 2026-03-30

[N/A][498327743] Medium CVE-2026-78941: Information leak in Core. Reported by Google on 2026-03-31

[N/A][498328139] Medium CVE-2026-79032: Improper input validation in Network. Reported by Google on 2026-03-31

[N/A][498367544] Medium CVE-2026-79109: Improper input validation in Printing. Reported by Google on 2026-04-01

[N/A][499007248] Medium CVE-2026-79256: Externally controlled reference in WebView. Reported by Google on 2026-04-02

[N/A][499068536] Medium CVE-2026-79237: Incorrect authorization in Navigation. Reported by Google on 2026-04-02

[N/A][499423269] Medium CVE-2026-78898: Incorrect authorization in Downloads. Reported by Google on 2026-04-04

[N/A][500038021] Medium CVE-2026-78985: Incorrect reference resolution in FileSystem. Reported by Google on 2026-04-06

[N/A][500492844] Medium CVE-2026-79028: Observable discrepancy in Network. Reported by Google on 2026-04-08

[N/A][501331457] Medium CVE-2026-79210: Use after free in Audio. Reported by Google on 2026-04-10

[N/A][501437087] Medium CVE-2026-79046: Race condition in Permissions. Reported by Google on 2026-04-10

[N/A][501572758] Medium CVE-2026-79129: Use after free in Sessions. Reported by Google on 2026-04-11

[N/A][501590191] Medium CVE-2026-78937: Use after free in Search. Reported by Google on 2026-04-11

[N/A][501594511] Medium CVE-2026-78987: Information leak in Canvas. Reported by Google on 2026-04-11

[N/A][501604761] Medium CVE-2026-78990: Use after free in Compositing. Reported by Google on 2026-04-11

[N/A][501637242] Medium CVE-2026-78909: Use after free in Views. Reported by Google on 2026-04-11

[N/A][501661601] Medium CVE-2026-79271: Information leak in DOM. Reported by Google on 2026-04-11

[N/A][501759192] Medium CVE-2026-79144: Information leak in Skia. Reported by Google on 2026-04-11

[N/A][501799770] Medium CVE-2026-79065: Improper input validation in Network. Reported by Google on 2026-04-12

[N/A][502082953] Medium CVE-2026-79192: Improper input validation in Variations. Reported by Google on 2026-04-13

[N/A][502101200] Medium CVE-2026-79140: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502109333] Medium CVE-2026-79128: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502139081] Medium CVE-2026-78942: Incorrect reference resolution in Loader. Reported by Google on 2026-04-13

[N/A][502232151] Medium CVE-2026-79116: Missing authorization in Viz. Reported by Google on 2026-04-13

[N/A][502344135] Medium CVE-2026-79006: Protection mechanism failure in HttpsUpgrades. Reported by Google on 2026-04-14

[N/A][502488051] Medium CVE-2026-79095: Information leak in Payments. Reported by Google on 2026-04-14

[N/A][502805441] Medium CVE-2026-79084: Inadequate encryption strength in Notifications. Reported by Google on 2026-04-15

[N/A][502888857] Medium CVE-2026-78991: Race condition in WebProtect. Reported by Google on 2026-04-15

[N/A][502918844] Medium CVE-2026-79248: Incorrect authorization in Input. Reported by Google on 2026-04-15

[TBD][503013378] Medium CVE-2026-78891: Buffer overflow in WebRTC. Reported by ngrunbaum on 2026-04-15

[N/A][503472696] Medium CVE-2026-79031: Improper resource exposure in Preload. Reported by Google on 2026-04-16

[N/A][503585863] Medium CVE-2026-79110: Missing authorization in Preload. Reported by Google on 2026-04-17

[N/A][503624894] Medium CVE-2026-79136: Incorrect authorization in ServiceWorker. Reported by Google on 2026-04-17

[N/A][503847023] Medium CVE-2026-78907: Incorrect authorization in WebProtect. Reported by Google on 2026-04-17

[N/A][504226770] Medium CVE-2026-79087: Injection in Chrome Tabs. Reported by Google on 2026-04-19

[N/A][504356442] Medium CVE-2026-79231: Buffer overflow in Media. Reported by Google on 2026-04-19

[N/A][504633668] Medium CVE-2026-78969: Uninitialized resource in Video. Reported by Google on 2026-04-20

[N/A][505951430] Medium CVE-2026-79137: Incorrect authorization in Extensions. Reported by Google on 2026-04-24

[N/A][505967344] Medium CVE-2026-79057: Race condition in Start. Reported by Google on 2026-04-24

[N/A][505991181] Medium CVE-2026-78894: Race condition in Payments. Reported by Google on 2026-04-24

[N/A][507483993] Medium CVE-2026-79264: Incorrect reference resolution in Preload. Reported by Google on 2026-04-28

[N/A][511260796] Medium CVE-2026-78910: Buffer overflow in V8. Reported by Google on 2026-05-08

[N/A][511736672] Medium CVE-2026-79066: Improper input validation in Navigation. Reported by Google on 2026-05-10

[N/A][511794959] Medium CVE-2026-79255: Improper input validation in WebRTC. Reported by Google on 2026-05-10

[N/A][511804361] Medium CVE-2026-79086: Missing authorization in CustomTabs. Reported by Google on 2026-05-10

[N/A][511806043] Medium CVE-2026-79038: Incorrect authorization in WebProtect. Reported by Google on 2026-05-10

[N/A][511819962] Medium CVE-2026-78940: Improper initialization in Network. Reported by Google on 2026-05-10

[N/A][511822878] Medium CVE-2026-79107: Incorrect authorization in TabGroups. Reported by Google on 2026-05-10

[N/A][512971896] Medium CVE-2026-79120: Uninitialized resource in ANGLE. Reported by Google on 2026-05-13

[N/A][513048462] Medium CVE-2026-79270: Uninitialized resource in ANGLE. Reported by Google on 2026-05-14

[N/A][513049445] Medium CVE-2026-79067: Missing authorization in Network. Reported by Google on 2026-05-14

[N/A][513119757] Medium CVE-2026-79213: Incorrect authorization in WebAppInstalls. Reported by Google on 2026-05-14

[N/A][513192145] Medium CVE-2026-78943: Improper input validation in Editing. Reported by Google on 2026-05-14

[N/A][513222422] Medium CVE-2026-79259: Improper input validation in Safebrowsing. Reported by Google on 2026-05-14

[N/A][513287677] Medium CVE-2026-79208: Missing authorization in HTTP2. Reported by Google on 2026-05-14

[N/A][513392351] Medium CVE-2026-79251: Improper input validation in Network. Reported by Google on 2026-05-15

[N/A][513607252] Medium CVE-2026-79226: Improper privilege management in Regional Capabilities. Reported by Google on 2026-05-15

[N/A][513608317] Medium CVE-2026-79042: Missing authorization in Payments. Reported by Google on 2026-05-15

[N/A][513608831] Medium CVE-2026-79122: Information leak in SignIn. Reported by Google on 2026-05-15

[N/A][513719741] Medium CVE-2026-79199: Incorrect authorization in Network. Reported by Google on 2026-05-16

[N/A][513737209] Medium CVE-2026-79013: Improper input validation in Sync. Reported by Google on 2026-05-16

[N/A][513745793] Medium CVE-2026-79074: Information leak in Network. Reported by Google on 2026-05-16

[N/A][513760788] Medium CVE-2026-79215: Integer overflow in WebGL. Reported by Google on 2026-05-16

[N/A][513786555] Medium CVE-2026-79049: Incorrect reference resolution in Passwords. Reported by Google on 2026-05-16

[N/A][513834155] Medium CVE-2026-79132: Improper input validation in Input. Reported by Google on 2026-05-16

[N/A][513836495] Medium CVE-2026-79201: Improper access control in Workers. Reported by Google on 2026-05-16

[N/A][513841856] Medium CVE-2026-79051: Incorrect authorization in Loader. Reported by Google on 2026-05-16

[N/A][513850062] Medium CVE-2026-79053: Missing authorization in Lighthouse. Reported by Google on 2026-05-16

[N/A][513918923] Medium CVE-2026-79285: Uninitialized resource in ANGLE. Reported by Google on 2026-05-17

[N/A][513923164] Medium CVE-2026-78906: Race condition in ANGLE. Reported by Google on 2026-05-17

[N/A][514006744] Medium CVE-2026-79250: UI misrepresentation in Navigation. Reported by Google on 2026-05-17

[N/A][514017820] Medium CVE-2026-79020: Out of bounds read in Skia. Reported by Google on 2026-05-17

[N/A][514055709] Medium CVE-2026-79217: Incorrect authorization in Mobile. Reported by Google on 2026-05-17

[N/A][514069975] Medium CVE-2026-79204: UI misrepresentation in Input. Reported by Google on 2026-05-17

[N/A][514078852] Medium CVE-2026-78912: UI misrepresentation in Browser. Reported by Google on 2026-05-17

[N/A][514439436] Medium CVE-2026-78955: Observable discrepancy in PerformanceAPIs. Reported by Google on 2026-05-18

[N/A][514454739] Medium CVE-2026-79143: Incorrect authorization in FileSystem. Reported by Google on 2026-05-19

[N/A][514508415] Medium CVE-2026-79241: Out of bounds read in GPU. Reported by Google on 2026-05-19

[N/A][514529599] Medium CVE-2026-78967: Missing authorization in BFCache. Reported by Google on 2026-05-19

[N/A][515477007] Medium CVE-2026-79214: Improper input validation in Preload. Reported by Google on 2026-05-21

[N/A][516398679] Medium CVE-2026-79228: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-25

[N/A][516665605] Medium CVE-2026-78953: Missing authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516824665] Medium CVE-2026-79229: Uninitialized resource in ANGLE. Reported by Google on 2026-05-26

[N/A][516899248] Medium CVE-2026-79002: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516921259] Medium CVE-2026-79272: Improper input validation in FindInPage. Reported by Google on 2026-05-27

[N/A][517045394] Medium CVE-2026-79127: Out of bounds write in ANGLE. Reported by Google on 2026-05-27

[N/A][517074167] Medium CVE-2026-79151: Improper input validation in Safebrowsing. Reported by Google on 2026-05-27

[N/A][517095594] Medium CVE-2026-78936: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-27

[N/A][517245017] Medium CVE-2026-78905: Type confusion in ANGLE. Reported by Google on 2026-05-27

[N/A][517364411] Medium CVE-2026-79050: Incorrect authorization in Network. Reported by Google on 2026-05-28

[N/A][517382613] Medium CVE-2026-79008: Improper input validation in GPU. Reported by Google on 2026-05-28

[N/A][517398863] Medium CVE-2026-78975: Incorrect authorization in DOM. Reported by Google on 2026-05-28

[N/A][517404644] Medium CVE-2026-79287: Observable discrepancy in Forms. Reported by Google on 2026-05-28

[N/A][517467117] Medium CVE-2026-79094: Race condition in Workers. Reported by Google on 2026-05-28

[N/A][517487890] Medium CVE-2026-79173: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-28

[N/A][517550421] Medium CVE-2026-78976: Improper input validation in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517580738] Medium CVE-2026-79276: Improper privilege management in FileSystem. Reported by Google on 2026-05-28

[N/A][517606780] Medium CVE-2026-79191: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-28

[N/A][517608454] Medium CVE-2026-79099: Missing authorization in Network. Reported by Google on 2026-05-28

[N/A][517634590] Medium CVE-2026-79024: Information leak in ServiceWorker. Reported by Google on 2026-05-28

[N/A][517655953] Medium CVE-2026-79193: Information leak in Canvas. Reported by Google on 2026-05-28

[N/A][517697155] Medium CVE-2026-79242: Observable discrepancy in HTML. Reported by Google on 2026-05-29

[N/A][517719358] Medium CVE-2026-79180: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-29

[N/A][517746687] Medium CVE-2026-79293: Information leak in Animation. Reported by Google on 2026-05-29

[N/A][517761566] Medium CVE-2026-79023: Incorrect authorization in Editing. Reported by Google on 2026-05-29

[N/A][517772510] Medium CVE-2026-79146: Information leak in CustomTabs. Reported by Google on 2026-05-29

[N/A][517774971] Medium CVE-2026-79238: Incorrect authorization in ServiceWorker. Reported by Google on 2026-05-29

[N/A][517910756] Medium CVE-2026-78949: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-29

[N/A][518023156] Medium CVE-2026-79291: Information leak in CSS. Reported by Google on 2026-05-29

[N/A][518035396] Medium CVE-2026-79283: UI misrepresentation in Geometry. Reported by Google on 2026-05-29

[N/A][518053893] Medium CVE-2026-78892: Incorrect authorization in Chromoting. Reported by Google on 2026-05-30

[N/A][518062961] Medium CVE-2026-79070: Incorrect reference resolution in Cache. Reported by Google on 2026-05-30

[N/A][518065628] Medium CVE-2026-79205: Incorrect authorization in Network. Reported by Google on 2026-05-30

[N/A][518078552] Medium CVE-2026-78903: Incomplete cleanup in SiteIsolation. Reported by Google on 2026-05-30

[N/A][518084889] Medium CVE-2026-78959: Improper handling of case sensitivity in FileSystem. Reported by Google on 2026-05-30

[N/A][518094442] Medium CVE-2026-79234: Injection in CSS. Reported by Google on 2026-05-30

[N/A][519369088] Medium CVE-2026-78983: Use after free in Views. Reported by Google on 2026-06-03

[N/A][519984038] Medium CVE-2026-79083: Improper enforcement of behavioral workflow in Media. Reported by Google on 2026-06-04

[TBD][520052954] Medium CVE-2026-78944: Use after free in DevTools. Reported by yupyon.itome on 2026-06-05

[N/A][520117546] Medium CVE-2026-79178: Incorrect authorization in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-04

[N/A][520121111] Medium CVE-2026-79059: Information leak in BFCache. Reported by Google on 2026-06-04

[N/A][520179360] Medium CVE-2026-79245: Use after free in UI. Reported by Google on 2026-06-05

[N/A][520464738] Medium CVE-2026-78978: Out of bounds read in ANGLE. Reported by Google on 2026-06-05

[N/A][520481800] Medium CVE-2026-79103: Incorrect reference resolution in Speech. Reported by Google on 2026-06-05

[N/A][520492291] Medium CVE-2026-79154: Missing authorization in DevTools. Reported by Google on 2026-06-05

[N/A][520504922] Medium CVE-2026-79230: Improper input validation in ANGLE. Reported by Google on 2026-06-05

[N/A][520516462] Medium CVE-2026-79068: Improper resource exposure in StreamsAPI. Reported by Google on 2026-06-05

[N/A][520542088] Medium CVE-2026-79269: Uninitialized resource in ANGLE. Reported by Google on 2026-06-05

[N/A][522077127] Medium CVE-2026-79085: Missing authorization in Network. Reported by Google on 2026-06-10

[N/A][522351802] Medium CVE-2026-79134: Incorrect authorization in GetUserMedia. Reported by Google on 2026-06-10

[N/A][522550059] Medium CVE-2026-79064: Use after free in Network. Reported by Google on 2026-06-11

[N/A][522791354] Medium CVE-2026-79003: Incorrect authorization in Device. Reported by Google on 2026-06-11

[N/A][522823211] Medium CVE-2026-79220: Information leak in Network. Reported by Google on 2026-06-11

[N/A][522957054] Medium CVE-2026-78951: Use after free in ServiceWorker. Reported by Google on 2026-06-11

[N/A][523232966] Medium CVE-2026-79249: Code injection in Bisection. Reported by Google on 2026-06-12

[N/A][523557855] Medium CVE-2026-79091: Use after free in Bluetooth. Reported by Google on 2026-06-13

[N/A][523661149] Medium CVE-2026-79265: Incomplete cleanup in GetUserMedia. Reported by Google on 2026-06-13

[N/A][523716748] Medium CVE-2026-78913: Use after free in Chromoting. Reported by Google on 2026-06-14

[N/A][524418836] Medium CVE-2026-79258: Incorrect authorization in WebXR. Reported by Google on 2026-06-16

[TBD][524520965] Medium CVE-2026-79211: Incorrect authorization in USB. Reported by hongan on 2026-06-16

[N/A][524541667] Medium CVE-2026-79252: Information leak in ServiceWorker. Reported by Google on 2026-06-16

[N/A][524822825] Medium CVE-2026-78962: Uninitialized resource in WebXR. Reported by Google on 2026-06-17

[N/A][525686865] Medium CVE-2026-78901: Race condition in V8. Reported by Google on 2026-06-19

[N/A][525689847] Medium CVE-2026-79097: Use after free in V8. Reported by Google on 2026-06-19

[N/A][532162132] Medium CVE-2026-79227: Type confusion in DevTools. Reported by Google on 2026-07-07

[N/A][532182486] Medium CVE-2026-79203: Improper input validation in DevTools. Reported by Google on 2026-07-07

[N/A][532914769] Medium CVE-2026-79033: Insufficient control flow management in DevTools. Reported by Google on 2026-07-09

[N/A][532917452] Medium CVE-2026-79139: Improper input validation in Media. Reported by Google on 2026-07-09

[N/A][532923954] Medium CVE-2026-79221: Uninitialized resource in Dawn. Reported by Google on 2026-07-09

[N/A][532957785] Medium CVE-2026-79034: Information leak in CORS. Reported by Google on 2026-07-09

[N/A][533093250] Medium CVE-2026-79075: Information leak in Geolocation. Reported by Google on 2026-07-09

[TBD][533917984] Medium CVE-2026-78960: Information leak in Extensions. Reported by Oran Simhony from Palo Alto Networks on 2026-07-12

[N/A][535374213] Medium CVE-2026-78984: Uninitialized resource in GPU. Reported by Google on 2026-07-16

[N/A][536428842] Medium CVE-2026-78963: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536428988] Medium CVE-2026-79004: Out of bounds read in Media. Reported by Google on 2026-07-19

[N/A][536444242] Medium CVE-2026-79182: Improper input validation in Media. Reported by Google on 2026-07-19

[TBD][536526176] Medium CVE-2026-79185: Information leak in DOM. Reported by avlidienbrunn on 2026-07-19

[N/A][536662911] Medium CVE-2026-79073: Improper state validation in Parser. Reported by Google on 2026-07-20

[N/A][537145191] Medium CVE-2026-79266: Use after free in DevTools. Reported by Google on 2026-07-21

[N/A][537846307] Medium CVE-2026-79025: Improper input validation in Workers. Reported by Google on 2026-07-22

[TBD][538969297] Medium CVE-2026-79141: Incorrect authorization in Browser. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-07-25

[$1,000][503048520] Low CVE-2026-78974: UI misrepresentation in Linux Toolkit Theming. Reported by Francesco Topol on 2026-04-16

[N/A][497232609] Low CVE-2026-79055: Information leak in Sharing. Reported by Google on 2026-03-28

[N/A][497256260] Low CVE-2026-79263: Race condition in Extensions. Reported by Google on 2026-03-28

[N/A][497493136] Low CVE-2026-79124: Information leak in Intents. Reported by Google on 2026-03-29

[N/A][497499482] Low CVE-2026-79184: Missing authorization in Preload. Reported by Google on 2026-03-29

[N/A][497876969] Low CVE-2026-79289: Improper control of a resource through its lifetime in Workers. Reported by Google on 2026-03-30

[N/A][500484520] Low CVE-2026-79001: Information leak in Bluetooth. Reported by Google on 2026-04-07

[N/A][501416859] Low CVE-2026-79077: Incorrect authorization in WebProtect. Reported by Google on 2026-04-10

[TBD][501881082] Low CVE-2026-78950: Integer overflow in WebRTC. Reported by Ashutosh on 2026-04-12

[N/A][502252964] Low CVE-2026-79196: Race condition in Editing. Reported by Google on 2026-04-13

[N/A][502514083] Low CVE-2026-79000: Improper input validation in DeviceBoundSessionCredentials. Reported by Google on 2026-04-14

[N/A][503720291] Low CVE-2026-78979: Race condition in Core. Reported by Google on 2026-04-17

[N/A][506539337] Low CVE-2026-79181: Observable discrepancy in Glic. Reported by Google on 2026-04-26

[N/A][513172858] Low CVE-2026-79190: Incorrect authorization in Extensions. Reported by Google on 2026-05-14

[N/A][513361380] Low CVE-2026-79206: Out of bounds read in FileSystem. Reported by Google on 2026-05-15

[N/A][513486883] Low CVE-2026-78897: Missing authorization in BrowserTag. Reported by Google on 2026-05-15

[N/A][513688690] Low CVE-2026-79119: Use after free in PDF. Reported by Google on 2026-05-15

[N/A][513792983] Low CVE-2026-79089: Race condition in Transactions Platform. Reported by Google on 2026-05-16

[N/A][513969378] Low CVE-2026-79147: Information leak in Skia. Reported by Google on 2026-05-17

[N/A][514010111] Low CVE-2026-79098: UI misrepresentation in PermissionElement. Reported by Google on 2026-05-17

[N/A][514038302] Low CVE-2026-79022: UI misrepresentation in Transactions Platform. Reported by Google on 2026-05-17

[N/A][514061923] Low CVE-2026-79233: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-17

[N/A][514408247] Low CVE-2026-79261: Incorrect authorization in Controls. Reported by Google on 2026-05-18

[N/A][516864349] Low CVE-2026-78977: Uninitialized resource in GPU. Reported by Google on 2026-05-26

[N/A][516950646] Low CVE-2026-79040: Uninitialized resource in GPU. Reported by Google on 2026-05-27

[N/A][517167020] Low CVE-2026-79273: Incorrect reference resolution in WebView. Reported by Google on 2026-05-27

[TBD][517394060] Low CVE-2026-79243: Improper input validation in ReadingList. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[TBD][517395590] Low CVE-2026-79123: Improper input validation in NTP Footer. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[N/A][517540292] Low CVE-2026-79005: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517673944] Low CVE-2026-79090: Improper privilege management in Actor. Reported by Google on 2026-05-29

[N/A][517718241] Low CVE-2026-78946: Incorrect authorization in Select. Reported by Google on 2026-05-29

[N/A][518125889] Low CVE-2026-78968: Missing authorization in Core. Reported by Google on 2026-05-30

[N/A][518249083] Low CVE-2026-79041: Missing authorization in Browser. Reported by Google on 2026-05-30

[N/A][519210950] Low CVE-2026-79284: UI misrepresentation in Core. Reported by Google on 2026-06-02

[N/A][519229463] Low CVE-2026-78896: Information leak in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][519242511] Low CVE-2026-79058: Missing authorization in Passwords. Reported by Google on 2026-06-02

[N/A][519246298] Low CVE-2026-79009: UI misrepresentation in UI. Reported by Google on 2026-06-02

[N/A][519254827] Low CVE-2026-79060: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][520002854] Low CVE-2026-79177: Incorrect authorization in Media. Reported by Google on 2026-06-04

[N/A][520016142] Low CVE-2026-78956: Type confusion in V8. Reported by Google on 2026-06-04

[TBD][520781436] Low CVE-2026-79239: Out of bounds read in Tint. Reported by Michal Andryskowski, Imperial College London on 2026-06-07

[N/A][522291712] Low CVE-2026-79015: Improper input validation in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522304549] Low CVE-2026-79108: UI misrepresentation in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-10

[N/A][522418913] Low CVE-2026-79056: Use after free in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522803735] Low CVE-2026-79018: Information leak in FoldableAPIs. Reported by Google on 2026-06-11

[N/A][523237735] Low CVE-2026-78980: Improper input validation in ReaderMode. Reported by Google on 2026-06-12

[N/A][523313378] Low CVE-2026-78947: Incomplete cleanup in Chromium. Reported by Microsoft Edge on 2026-06-12

[N/A][523572877] Low CVE-2026-79244: Use after free in Animation. Reported by Google on 2026-06-13

[TBD][524864599] Low CVE-2026-79112: Out of bounds read in Skia. Reported by Quan Huynh x Amaterasu on 2026-06-17

[N/A][525311654] Low CVE-2026-79246: Information leak in DataTransfer. Reported by Google on 2026-06-18

[TBD][530816571] Low CVE-2026-79223: Integer overflow in Chromium. Reported by Youngjin Ju on 2026-07-03

[N/A][531245718] Low CVE-2026-79045: Type confusion in V8. Reported by Google on 2026-07-04

[N/A][531297707] Low CVE-2026-79197: Use after free in V8. Reported by Google on 2026-07-05

[N/A][532303080] Low CVE-2026-79148: Off-by-one error in DevTools. Reported by Google on 2026-07-08

[N/A][533001362] Low CVE-2026-79125: Information leak in XR. Reported by Google on 2026-07-09

[N/A][533014006] Low CVE-2026-79207: Information leak in Passwords. Reported by Google on 2026-07-09

[N/A][533021205] Low CVE-2026-79017: Race condition in Extensions. Reported by Google on 2026-07-09

[N/A][533046298] Low CVE-2026-79105: Improper input validation in Mobile. Reported by Google on 2026-07-09

[N/A][533059149] Low CVE-2026-79225: Incorrect authorization in Browser. Reported by Google on 2026-07-09

[N/A][533060125] Low CVE-2026-79021: Missing authorization in InterestGroups. Reported by Google on 2026-07-09

[N/A][533075126] Low CVE-2026-79133: Incorrect authorization in Forms. Reported by Google on 2026-07-09

[N/A][533079345] Low CVE-2026-79179: Incorrect authorization in DOM. Reported by Google on 2026-07-09

[N/A][533083384] Low CVE-2026-79152: Incorrect authorization in CustomTabs. Reported by Google on 2026-07-09

[N/A][533121405] Low CVE-2026-78981: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533123348] Low CVE-2026-78957: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533408915] Low CVE-2026-79126: Incorrect provision of specified functionality in Proxy. Reported by Google on 2026-07-10

[N/A][533418127] Low CVE-2026-78915: Race condition in Enterprise. Reported by Google on 2026-07-10

[N/A][533511921] Low CVE-2026-79253: Improper input validation in Network. Reported by Google on 2026-07-10

[N/A][533511967] Low CVE-2026-79260: Improper input validation in Cookies. Reported by Google on 2026-07-10

[N/A][534556413] Low CVE-2026-79254: Incorrect reference resolution in CustomTabs. Reported by Google on 2026-07-14

[N/A][536166543] Low CVE-2026-78914: Uninitialized resource in Skia. Reported by Google on 2026-07-18

[N/A][539341100] Low CVE-2026-78964: Use after free in Sync. Reported by Google on 2026-07-27


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Stable Channel Update for Desktop

20 Augustus 2026 om 22:28

The Stable channel has been updated to 151.0.7922.173/.174 for Windows and Mac and 151.0.7922.173 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 7 security fixes. Please see the Chrome Security Page for more information.


[N/A][522819252] Critical CVE-2026-76017: Use after free in Chromoting. Reported by Google on 2026-06-11

[N/A][513757918] High CVE-2026-76018: Privilege elevation in Import. Reported by Google on 2026-05-16

[TBD][539032888] High CVE-2026-76019: Incorrect authorization in Workers. Reported by Anonymous on 2026-07-26

[TBD][541837151] High CVE-2026-76020: Race condition in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-03

[N/A][541854084] High CVE-2026-76021: Use after free in DOM. Reported by Google BigSleep@Grape on 2026-08-02

[TBD][543798025] High CVE-2026-76022: Buffer overflow in Network. Reported by 0xAlessandro on 2026-08-07

[TBD][545124048] High CVE-2026-76023: Improper resource control in Linux Toolkit Theming. Reported by Keita Sode and Daisuke Hatakeyama of SYZD Research on 2026-08-11


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Early Stable Update for Desktop

19 Augustus 2026 om 18:58

The Stable channel has been updated to 152.0.7977.54/.55 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

18 Augustus 2026 om 22:13

Β The Stable channel has been updated to 151.0.7922.169/.170 for Windows and Mac and 151.0.7922.169 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 15 security fixes. Please see the Chrome Security Page for more information.


[N/A][534923522] Critical CVE-2026-76034: Buffer overflow in WebGL. Reported by Google on 2026-07-15

[N/A][540087398] Critical CVE-2026-76036: Buffer overflow in Dawn. Reported by Google on 2026-07-28

[N/A][516715010] High CVE-2026-76033: Inappropriate implementation in CORS. Reported by Google on 2026-05-26

[N/A][517612295] High CVE-2026-76037: Link following in CredentialProvider. Reported by Google on 2026-05-28

[N/A][522732244] High CVE-2026-76044: Race condition in USB. Reported by Google on 2026-06-11

[N/A][525167753] High CVE-2026-76039: Incorrect reference resolution in Core. Reported by Google on 2026-06-18

[N/A][534862220] High CVE-2026-76040: Use after free in Browser. Reported by Google on 2026-07-14

[N/A][536439844] High CVE-2026-76035: Inappropriate implementation in Media. Reported by Google on 2026-07-19

[N/A][536460270] High CVE-2026-76042: Use of uninitialized resource in GPU. Reported by Google on 2026-07-19

[N/A][536581050] High CVE-2026-76046: Buffer overflow in ANGLE. Reported by Google on 2026-07-19

[TBD][539350801] High CVE-2026-76043: Incorrect calculation in V8. Reported by Raghav Maheshwari on 2026-07-27

[N/A][540027341] High CVE-2026-76041: Information leak in Skia. Reported by Google on 2026-07-28

[TBD][541251902] High CVE-2026-76047: Type confusion in V8. Reported by ywatanabee on 2026-07-31

[TBD][541926503] High CVE-2026-76038: Type confusion in V8. Reported by un3xploitable && GF on 2026-08-03

[TBD][543082390] High CVE-2026-76045: Use after free in WebGL. Reported by OpenAI Codex Security (amyb) on 2026-08-05


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Extended Stable Update for Desktop

18 Augustus 2026 om 21:28

The Extended Stable channel has been updated to 150.0.7871.250 for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome
  •  

Early Stable Update for Desktop

12 Augustus 2026 om 23:11

The Stable channel has been updated to 152.0.7977.42/.43 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Extended Stable Update for Desktop

11 Augustus 2026 om 23:39

The Extended Stable channel has been updated to 150.0.7871.230Β for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome
  •  

Stable Channel Update for Desktop

11 Augustus 2026 om 23:22
The Stable channel has been updated to 151.0.7922.137/.138 for Windows and Mac and 151.0.7922.137 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 

Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 5 security fixes. Please see the Chrome Security Page for more information.

[$500][535000102] High CVE-2026-19556: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-07-15
[N/A][534867485] High CVE-2026-19557: Use after free in TabStrip. Reported by Google on 2026-07-14
[N/A][536676756] High CVE-2026-19558: Use after free in Extensions. Reported by @bean5oup on 2026-07-20
[N/A][540100588] High CVE-2026-19559: Use after free in HTML. Reported by Google on 2026-07-28
[N/A][540482895] High CVE-2026-19560: Use after free in Blink. Reported by WinD39 - Huynh Dinh Vu on 2026-07-30

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

6 Augustus 2026 om 22:26

The Stable channel has been updated to 151.0.7922.108/.109 for Windows and Mac and 151.0.7922.108 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 


Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 41 security fixes. Please see the Chrome Security Page for more information.


[TBD][499602793] Critical CVE-2026-19137: Use after free in WebGL. Reported by anonymous on 2026-04-05

[N/A][524824288] Critical CVE-2026-19149: Use after free in Aura. Reported by Google on 2026-06-17

[N/A][532941869] Critical CVE-2026-19154: Use after free in Skia. Reported by Google on 2026-07-09

[N/A][534903095] Critical CVE-2026-19157: Out of bounds write in ANGLE. Reported by Google on 2026-07-14

[TBD][537729021] Critical CVE-2026-19170: Use after free in WebGL. Reported by Muhammad Alifa Ramdhan, Pan ZhenPeng, Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd. on 2026-07-22

[N/A][537838324] Critical CVE-2026-19172: Use after free in Views. Reported by Google on 2026-07-22

[$5000][537390933] High CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks. Reported by Sven Dysthe (@svn-dys) on 2026-07-21

[$500][536945254] High CVE-2026-19168: Inappropriate implementation in V8. Reported by XBOW and triaged by AndrΓ©s Luksenberg on 2026-07-20

[N/A][500097298] High CVE-2026-19138: Heap buffer overflow in CrashReporting. Reported by Google on 2026-04-06

[N/A][511731805] High CVE-2026-19139: Race in CredentialProvider. Reported by Google on 2026-05-10

[N/A][513044017] High CVE-2026-19140: Use after free in GPU. Reported by Google on 2026-05-14

[N/A][513602949] High CVE-2026-19141: Use after free in Resources. Reported by Google on 2026-05-15

[N/A][515428251] High CVE-2026-19142: Use after free in Views. Reported by Google on 2026-05-21

[N/A][517772612] High CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs. Reported by Google on 2026-05-29

[N/A][520167277] High CVE-2026-19144: Use after free in HTML. Reported by Google on 2026-06-05

[N/A][521878431] High CVE-2026-19145: Use after free in Translate. Reported by Google on 2026-06-09

[N/A][523713150] High CVE-2026-19146: Uninitialized Use in GPU. Reported by Google on 2026-06-14

[N/A][524439798] High CVE-2026-19147: Use after free in Aura. Reported by Google on 2026-06-16

[N/A][524460000] High CVE-2026-19148: Out of bounds write in GPU. Reported by Google on 2026-06-16

[N/A][526380803] High CVE-2026-19150: Inappropriate implementation in V8. Reported by Google on 2026-06-22

[N/A][530663440] High CVE-2026-19151: Use after free in V8. Reported by Google on 2026-07-02

[N/A][531165110] High CVE-2026-19152: Inappropriate implementation in Navigation. Reported by Google on 2026-07-04

[N/A][532939327] High CVE-2026-19153: Insufficient validation of untrusted input in Workers. Reported by Google on 2026-07-09

[N/A][533053621] High CVE-2026-19155: Use after free in Payments. Reported by Google on 2026-07-09

[TBD][533331920] High CVE-2026-19156: Heap buffer overflow in Base. Reported by Viktoria Zlatinova on 2026-07-10

[N/A][535749174] High CVE-2026-19158: Use after free in Views. Reported by Google on 2026-07-17

[N/A][536067175] High CVE-2026-19159: Use after free in Views. Reported by Google on 2026-07-17

[N/A][536068737] High CVE-2026-19160: Uninitialized Use in Skia. Reported by Google on 2026-07-17

[N/A][536165038] High CVE-2026-19161: Uninitialized Use in Skia. Reported by Google on 2026-07-18

[TBD][536271629] High CVE-2026-19162: Out of bounds write in V8. Reported by OpenAI Codex Security (amyb) on 2026-07-19

[N/A][536449742] High CVE-2026-19163: Use after free in Media. Reported by Google on 2026-07-19

[N/A][536470854] High CVE-2026-19164: Insufficient validation of untrusted input in Codecs. Reported by Google on 2026-07-19

[TBD][536512612] High CVE-2026-19165: Use after free in Extensions. Reported by @bean5oup on 2026-07-19

[TBD][536584251] High CVE-2026-19166: Use after free in Web Authentication. Reported by heesun on 2026-07-20

[N/A][536666274] High CVE-2026-19167: Integer overflow in GPU. Reported by Google on 2026-07-20

[N/A][537832446] High CVE-2026-19171: Use after free in Media. Reported by Google on 2026-07-22

[TBD][538332338] High CVE-2026-19173: Out of bounds write in Skia. Reported by Vu Van Tien (@n0_Be3r) on 2026-07-24

[TBD][538378084] High CVE-2026-19174: Integer overflow in V8. Reported by Seunghyun Lee (@0x10n) of QED Audit (qedaudit.io) on 2026-07-24

[N/A][540138836] High CVE-2026-19175: Use after free in Payments. Reported by Google on 2026-07-29

[TBD][540157141] High CVE-2026-19176: Use after free in Skia. Reported by WinD39 - Huynh Dinh Vu on 2026-07-29

[TBD][540289900] High CVE-2026-19177: Insufficient validation of untrusted input in UI. Reported by Fabian Wahle (Hap Security) on 2026-07-29


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Extended Stable Update for Desktop

6 Augustus 2026 om 19:24

The Extended Stable channel has been updated to 150.0.7871.224 for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Daniel Yip
Google Chrome



  •  

Stable Channel Update for Desktop

4 Augustus 2026 om 22:20

The Stable channel has been updated to 151.0.7922.75/.76 for Windows and Mac and 151.0.7922.75 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

30 Juli 2026 om 02:03

Β The Stable channel has been updated to 151.0.7922.71/.72 for Windows and Mac andΒ 151.0.7922.71Β for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 370 security fixes. Please see the Chrome Security Page for more information.

[N/A][514442821] Critical CVE-2026-17650: Use after free in Compositing. Reported by Google on 2026-05-18

[N/A][517307966] Critical CVE-2026-17651: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-05-28

[N/A][519262990] Critical CVE-2026-17652: Use after free in Views. Reported by Google on 2026-06-02

[N/A][520514458] Critical CVE-2026-17653: Use after free in Skia. Reported by Google on 2026-06-05

[N/A][522314940] Critical CVE-2026-17654: Race in Updater. Reported by Google on 2026-06-10

[N/A][522556145] Critical CVE-2026-17655: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-06-11

[N/A][523725277] Critical CVE-2026-17656: Use after free in Ozone. Reported by Google on 2026-06-14

[$36000][502293787] High CVE-2026-17657: Use after free in Navigation. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-14

[$1000][523030583] High CVE-2026-17658: Use after free in V8. Reported by Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security on 2026-06-12

[N/A][495463654] High CVE-2026-17659: Inappropriate implementation in SiteIsolation. Reported by Google on 2026-03-23

[N/A][497428001] High CVE-2026-17660: Insufficient validation of untrusted input in Network. Reported by Google on 2026-03-29

[N/A][497451790] High CVE-2026-17661: Use after free in Loader. Reported by Google on 2026-03-29

[N/A][497491557] High CVE-2026-17662: Insufficient policy enforcement in Prefetch. Reported by Google on 2026-03-29

[N/A][500225310] High CVE-2026-17663: Insufficient validation of untrusted input in GPU. Reported by Google on 2026-04-07

[N/A][500554346] High CVE-2026-17664: Insufficient validation of untrusted input in Loader. Reported by Google on 2026-04-08

[N/A][511277457] High CVE-2026-17665: Use after free in V8. Reported by Google on 2026-05-08

[N/A][511761758] High CVE-2026-17666: Cryptographic Flaw in Enterprise. Reported by Google on 2026-05-10

[N/A][513043537] High CVE-2026-17667: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14

[N/A][513134019] High CVE-2026-17668: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14

[N/A][513142464] High CVE-2026-17669: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-14

[N/A][513228974] High CVE-2026-17670: Use after free in Views. Reported by Google on 2026-05-14

[N/A][513257423] High CVE-2026-17671: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-14

[N/A][513375270] High CVE-2026-17672: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-05-15

[N/A][513735177] High CVE-2026-17673: Integer overflow in QUIC. Reported by Google on 2026-05-16

[N/A][513791232] High CVE-2026-17674: Inappropriate implementation in HTML. Reported by Google on 2026-05-16

[N/A][513920258] High CVE-2026-17675: Out of bounds write in ANGLE. Reported by Google on 2026-05-17

[N/A][513920298] High CVE-2026-17676: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17

[N/A][513921488] High CVE-2026-17677: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17

[N/A][515452019] High CVE-2026-17678: Out of bounds read in ANGLE. Reported by Google on 2026-05-21

[N/A][516430649] High CVE-2026-17679: Insufficient validation of untrusted input in Print Preview. Reported by Google on 2026-05-25

[N/A][516486611] High CVE-2026-17680: Heap buffer overflow in Color. Reported by Google on 2026-05-25

[N/A][516813184] High CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication. Reported by Google on 2026-05-26

[N/A][516837126] High CVE-2026-17682: Integer overflow in ANGLE. Reported by Google on 2026-05-26

[N/A][516887576] High CVE-2026-17683: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-26

[N/A][516894682] High CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-26

[N/A][516910278] High CVE-2026-17685: Use after free in Autofill. Reported by Google on 2026-05-27

[N/A][516917065] High CVE-2026-17686: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-27

[N/A][516985726] High CVE-2026-17687: Type Confusion in ANGLE. Reported by Google on 2026-05-27

[N/A][517016413] High CVE-2026-17688: Use after free in Input. Reported by Google on 2026-05-27

[N/A][517045160] High CVE-2026-17689: Uninitialized Use in ANGLE. Reported by Google on 2026-05-27

[N/A][517129282] High CVE-2026-17690: Insufficient validation of untrusted input in PDF. Reported by Google on 2026-05-27

[N/A][517321292] High CVE-2026-17691: Out of bounds write in ANGLE. Reported by Google on 2026-05-28

[N/A][517350808] High CVE-2026-17692: Use after free in DataTransfer. Reported by Google on 2026-05-28

[N/A][517448723] High CVE-2026-17693: Inappropriate implementation in FileSystem. Reported by Google on 2026-05-28

[N/A][517511796] High CVE-2026-17694: Use after free in DOM. Reported by Google on 2026-05-28

[N/A][517543052] High CVE-2026-17695: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-28

[N/A][517550034] High CVE-2026-17696: Side-channel information leakage in Media. Reported by Google on 2026-05-28

[N/A][517575864] High CVE-2026-17697: Type Confusion in ANGLE. Reported by Google on 2026-05-28

[N/A][517670731] High CVE-2026-17698: Insufficient validation of untrusted input in UI. Reported by Google on 2026-05-29

[N/A][517785292] High CVE-2026-17699: Use after free in Views. Reported by Google on 2026-05-29

[N/A][517789833] High CVE-2026-17700: Insufficient validation of untrusted input in Actor. Reported by Google on 2026-05-29

[N/A][517972648] High CVE-2026-17701: Out of bounds read in ANGLE. Reported by Google on 2026-05-29

[N/A][517973093] High CVE-2026-17702: Inappropriate implementation in Skia. Reported by Google on 2026-05-29

[N/A][518051499] High CVE-2026-17703: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][519259107] High CVE-2026-17704: Use after free in ANGLE. Reported by Google on 2026-06-02

[TBD][519665978] High CVE-2026-17705: Integer overflow in libxml. Reported by ebassi of Igalia on 2026-06-04

[N/A][519693032] High CVE-2026-17706: Insufficient validation of untrusted input in Media. Reported by Google on 2026-06-03

[N/A][519701233] High CVE-2026-17707: Uninitialized Use in Media. Reported by Google on 2026-06-03

[N/A][519738647] High CVE-2026-17708: Use after free in Audio. Reported by Google on 2026-06-04

[N/A][519981494] High CVE-2026-17709: Race in Downloads. Reported by Google on 2026-06-04

[N/A][519991712] High CVE-2026-17710: Inappropriate implementation in MHTML. Reported by Google on 2026-06-04

[N/A][519996040] High CVE-2026-17711: Race in Downloads. Reported by Google on 2026-06-04

[N/A][520535595] High CVE-2026-17712: Race in Skia. Reported by Google on 2026-06-05

[N/A][520572766] High CVE-2026-17713: Insufficient validation of untrusted input in Accessibility. Reported by Google on 2026-06-06

[N/A][521293438] High CVE-2026-17714: Uninitialized Use in ANGLE. Reported by Google on 2026-06-08

[N/A][521491778] High CVE-2026-17715: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08

[N/A][521866061] High CVE-2026-17716: Use after free in Updater. Reported by Google on 2026-06-09

[N/A][522063116] High CVE-2026-17717: Integer overflow in ANGLE. Reported by Google on 2026-06-10

[N/A][522079372] High CVE-2026-17718: Use after free in ANGLE. Reported by Google on 2026-06-10

[N/A][522304853] High CVE-2026-17719: Use after free in Input. Reported by Google on 2026-06-10

[N/A][522545249] High CVE-2026-17720: Insufficient policy enforcement in Passwords. Reported by Google on 2026-06-11

[N/A][523495723] High CVE-2026-17721: Out of bounds write in ANGLE. Reported by Google on 2026-06-13

[N/A][523592755] High CVE-2026-17722: Object lifecycle issue in WebView. Reported by Google on 2026-06-13

[N/A][523718303] High CVE-2026-17723: Use after free in Media. Reported by Google on 2026-06-14

[N/A][523720739] High CVE-2026-17724: Race in Chrome for iOS. Reported by Google on 2026-06-14

[TBD][528501127] High CVE-2026-17725: Type Confusion in V8. Reported by nh.dev2022 on 2026-06-27

[N/A][529867799] High CVE-2026-17726: Integer overflow in WebGL. Reported by Google on 2026-06-30

[N/A][529932631] High CVE-2026-17727: Out of bounds write in WebGL. Reported by Google on 2026-07-01

[$10000][461167648] Medium CVE-2026-17728: Inappropriate implementation in Extensions. Reported by Suhas S P on 2025-11-16

[$5000][503801946] Medium CVE-2026-17758: Heap buffer overflow in Dawn. Reported by Hyeonjun Ahn (@_deayzl) on 2026-04-18

[$2000][476646486] Medium CVE-2026-17732: Inappropriate implementation in SVG. Reported by Lyra Rebane (rebane2001) on 2026-01-17

[$500][520656237] Medium CVE-2026-17729: Use after free in V8. Reported by wang1r && lhfff on 2026-06-07

[N/A][40057032] Medium CVE-2026-17730: Side-channel information leakage in Autofill. Reported by Google on 2021-08-26

[TBD][463551850] Medium CVE-2026-17731: Inappropriate implementation in Autofill. Reported by Manojkumar Jaganathan Aka TheWhiteEvil with HackerBro Technologies on 2025-11-25

[N/A][495793059] Medium CVE-2026-17733: Inappropriate implementation in QUIC. Reported by Google on 2026-03-24

[N/A][496304083] Medium CVE-2026-17734: Inappropriate implementation in Autofill. Reported by Google on 2026-03-25

[N/A][496569497] Medium CVE-2026-17735: Insufficient validation of untrusted input in BFCache. Reported by Google on 2026-03-26

[N/A][496715442] Medium CVE-2026-17736: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-03-27

[N/A][498000415] Medium CVE-2026-17737: Use after free in Bluetooth. Reported by Google on 2026-03-31

[N/A][498079379] Medium CVE-2026-17738: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-03-31

[N/A][498353463] Medium CVE-2026-17739: Insufficient policy enforcement in Extensions. Reported by Google on 2026-03-31

[N/A][498827800] Medium CVE-2026-17740: Uninitialized Use in ANGLE. Reported by Google on 2026-04-02

[N/A][498877660] Medium CVE-2026-17741: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-04-02

[N/A][499003233] Medium CVE-2026-17742: Insufficient policy enforcement in Payments. Reported by Google on 2026-04-02

[N/A][499204022] Medium CVE-2026-17743: Insufficient policy enforcement in ControlledFrame. Reported by Google on 2026-04-03

[N/A][500137309] Medium CVE-2026-17744: Inappropriate implementation in File Input. Reported by Google on 2026-04-07

[N/A][500172224] Medium CVE-2026-17745: Out of bounds read in Skia. Reported by Google on 2026-04-07

[N/A][500390256] Medium CVE-2026-17746: Use after free in GPU. Reported by Google on 2026-04-07

[N/A][500472958] Medium CVE-2026-17747: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-04-07

[N/A][500494349] Medium CVE-2026-17748: Inappropriate implementation in Extensions. Reported by Google on 2026-04-08

[N/A][500526602] Medium CVE-2026-17749: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-04-08

[N/A][500560234] Medium CVE-2026-17750: Use after free in ANGLE. Reported by Google on 2026-04-08

[N/A][501591293] Medium CVE-2026-17751: Inappropriate implementation in AdFilter. Reported by Google on 2026-04-11

[N/A][501619207] Medium CVE-2026-17752: Use after free in Views. Reported by Google on 2026-04-11

[N/A][501628355] Medium CVE-2026-17753: Inappropriate implementation in Autofill. Reported by Google on 2026-04-11

[N/A][501675996] Medium CVE-2026-17754: Inappropriate implementation in Blink. Reported by Google on 2026-04-11

[N/A][501854535] Medium CVE-2026-17755: Incorrect security UI in Extensions. Reported by Google on 2026-04-12

[N/A][501980797] Medium CVE-2026-17756: Insufficient policy enforcement in Presentation. Reported by Google on 2026-04-13

[N/A][502351526] Medium CVE-2026-17757: Uninitialized Use in Skia. Reported by Google on 2026-04-14

[N/A][504650654] Medium CVE-2026-17759: Uninitialized Use in Codecs. Reported by Google on 2026-04-20

[N/A][506473189] Medium CVE-2026-17760: Side-channel information leakage in NoStatePrefetch. Reported by Google on 2026-04-25

[N/A][508249524] Medium CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][508251844] Medium CVE-2026-17762: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][511738693] Medium CVE-2026-17763: Inappropriate implementation in GPU. Reported by Google on 2026-05-10

[N/A][511754400] Medium CVE-2026-17764: Inappropriate implementation in FedCM. Reported by Google on 2026-05-10

[N/A][511765328] Medium CVE-2026-17765: Inappropriate implementation in WebProtect. Reported by Google on 2026-05-10

[N/A][511799537] Medium CVE-2026-17766: Insufficient validation of untrusted input in Clipboard. Reported by Google on 2026-05-10

[N/A][511822402] Medium CVE-2026-17767: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-05-10

[N/A][512999037] Medium CVE-2026-17768: Insufficient validation of untrusted input in WebSockets. Reported by Google on 2026-05-13

[N/A][513022076] Medium CVE-2026-17769: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14

[N/A][513103345] Medium CVE-2026-17770: Out of bounds read in Media. Reported by Google on 2026-05-14

[N/A][513160525] Medium CVE-2026-17771: Uninitialized Use in Skia. Reported by Google on 2026-05-14

[N/A][513197846] Medium CVE-2026-17772: Out of bounds read in WebGL. Reported by Google on 2026-05-14

[N/A][513232523] Medium CVE-2026-17773: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14

[N/A][513323066] Medium CVE-2026-17774: Insufficient validation of untrusted input in Variations. Reported by Google on 2026-05-14

[N/A][513363822] Medium CVE-2026-17775: Inappropriate implementation in PresentationAPI. Reported by Google on 2026-05-15

[N/A][513404032] Medium CVE-2026-17776: Policy bypass in Receiver. Reported by Google on 2026-05-15

[N/A][513462236] Medium CVE-2026-17777: Inappropriate implementation in Autofill. Reported by Google on 2026-05-15

[N/A][513467993] Medium CVE-2026-17778: Use after free in Extensions. Reported by Google on 2026-05-15

[N/A][513478933] Medium CVE-2026-17779: Inappropriate implementation in Site Isolation. Reported by Google on 2026-05-15

[N/A][513485951] Medium CVE-2026-17780: Inappropriate implementation in Isolated Web Apps. Reported by Google on 2026-05-15

[N/A][513502990] Medium CVE-2026-17781: Inappropriate implementation in Extensions. Reported by Google on 2026-05-15

[N/A][513507830] Medium CVE-2026-17782: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-15

[N/A][513532735] Medium CVE-2026-17783: Inappropriate implementation in Loader. Reported by Google on 2026-05-15

[N/A][513694032] Medium CVE-2026-17784: Use after free in Audio. Reported by Google on 2026-05-16

[N/A][513769898] Medium CVE-2026-17785: Uninitialized Use in ANGLE. Reported by Google on 2026-05-16

[N/A][513770449] Medium CVE-2026-17786: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513783632] Medium CVE-2026-17787: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513824957] Medium CVE-2026-17788: Inappropriate implementation in Blink. Reported by Google on 2026-05-16

[N/A][513855922] Medium CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-16

[N/A][513919931] Medium CVE-2026-17790: Uninitialized Use in ANGLE. Reported by Google on 2026-05-17

[N/A][514006959] Medium CVE-2026-17791: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-17

[N/A][514019823] Medium CVE-2026-17792: Inappropriate implementation in Credential Management. Reported by Google on 2026-05-17

[N/A][514063859] Medium CVE-2026-17793: Inappropriate implementation in Messages. Reported by Google on 2026-05-17

[N/A][514067070] Medium CVE-2026-17794: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-05-17

[TBD][514242889] Medium CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia. Reported by Mihnea Nicolau on 2026-05-18

[N/A][514427844] Medium CVE-2026-17796: Side-channel information leakage in WebXR. Reported by Google on 2026-05-18

[N/A][514441966] Medium CVE-2026-17797: Inappropriate implementation in CSS. Reported by Google on 2026-05-18

[N/A][514460133] Medium CVE-2026-17798: Inappropriate implementation in Cast. Reported by Google on 2026-05-19

[N/A][514461031] Medium CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing. Reported by Google on 2026-05-19

[N/A][514480948] Medium CVE-2026-17800: Side-channel information leakage in MediaRecording. Reported by Google on 2026-05-19

[N/A][514482938] Medium CVE-2026-17801: Out of bounds memory access in ANGLE. Reported by Google on 2026-05-19

[N/A][514512198] Medium CVE-2026-17802: Side-channel information leakage in GPU. Reported by Google on 2026-05-19

[N/A][515438919] Medium CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive. Reported by Google on 2026-05-21

[N/A][515448947] Medium CVE-2026-17804: Use after free in Media. Reported by Google on 2026-05-21

[N/A][516420806] Medium CVE-2026-17805: Insufficient policy enforcement in Glic. Reported by Google on 2026-05-25

[N/A][516433058] Medium CVE-2026-17806: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-25

[N/A][516763884] Medium CVE-2026-17807: Use after free in V8. Reported by Google on 2026-05-26

[N/A][516778390] Medium CVE-2026-17808: Uninitialized Use in WebGL. Reported by Google on 2026-05-26

[N/A][516813317] Medium CVE-2026-17809: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-26

[N/A][516882109] Medium CVE-2026-17810: Uninitialized Use in Dawn. Reported by Google on 2026-05-26

[N/A][516954622] Medium CVE-2026-17811: Use after free in ANGLE. Reported by Google on 2026-05-27

[N/A][517101596] Medium CVE-2026-17812: Inappropriate implementation in DigitalCredentials. Reported by Google on 2026-05-27

[N/A][517184957] Medium CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-05-27

[N/A][517312048] Medium CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517427352] Medium CVE-2026-17815: Insufficient policy enforcement in GuestView. Reported by Google on 2026-05-28

[N/A][517429672] Medium CVE-2026-17816: Inappropriate implementation in Speech. Reported by Google on 2026-05-28

[N/A][517461759] Medium CVE-2026-17817: Inappropriate implementation in ReportingAndNEL. Reported by Google on 2026-05-28

[N/A][517466133] Medium CVE-2026-17818: Inappropriate implementation in Network. Reported by Google on 2026-05-28

[N/A][517487028] Medium CVE-2026-17819: Inappropriate implementation in WebAppInstalls. Reported by Google on 2026-05-28

[N/A][517493101] Medium CVE-2026-17820: Insufficient policy enforcement in Autofill. Reported by Google on 2026-05-28

[N/A][517597914] Medium CVE-2026-17821: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-28

[N/A][517621178] Medium CVE-2026-17822: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517628043] Medium CVE-2026-17823: Insufficient policy enforcement in WebXR. Reported by Google on 2026-05-28

[N/A][517655543] Medium CVE-2026-17824: Insufficient policy enforcement in ServiceWorker. Reported by Google on 2026-05-28

[N/A][517675979] Medium CVE-2026-17825: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29

[N/A][517690521] Medium CVE-2026-17826: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[N/A][517693726] Medium CVE-2026-17827: Inappropriate implementation in CSS. Reported by Google on 2026-05-29

[N/A][517702279] Medium CVE-2026-17828: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[N/A][517705103] Medium CVE-2026-17829: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29

[N/A][517710397] Medium CVE-2026-17830: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[N/A][517714728] Medium CVE-2026-17831: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-29

[N/A][517723319] Medium CVE-2026-17832: Use after free in ANGLE. Reported by Google on 2026-05-29

[N/A][517779123] Medium CVE-2026-17833: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29

[N/A][517793801] Medium CVE-2026-17834: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29

[N/A][517801739] Medium CVE-2026-17835: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29

[TBD][517972812] Medium CVE-2026-17836: Use after free in V8. Reported by yupyon.itome on 2026-05-30

[N/A][517978932] Medium CVE-2026-17837: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-29

[N/A][518075952] Medium CVE-2026-17838: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518080978] Medium CVE-2026-17839: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518082162] Medium CVE-2026-17840: Incorrect security UI in Passwords. Reported by Google on 2026-05-30

[N/A][518088219] Medium CVE-2026-17841: Race in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518089997] Medium CVE-2026-17842: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518103887] Medium CVE-2026-17843: Inappropriate implementation in CSS. Reported by Google on 2026-05-30

[N/A][518111542] Medium CVE-2026-17844: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-30

[N/A][518112775] Medium CVE-2026-17845: Inappropriate implementation in CSS. Reported by Google on 2026-05-30

[N/A][518121320] Medium CVE-2026-17846: Inappropriate implementation in Media. Reported by Google on 2026-05-30

[N/A][518243653] Medium CVE-2026-17847: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-30

[TBD][518284253] Medium CVE-2026-17848: Insufficient validation of untrusted input in Codecs. Reported by Ameen Basha M K on 2026-05-31

[N/A][518812672] Medium CVE-2026-17849: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-01

[TBD][519078527] Medium CVE-2026-17850: Inappropriate implementation in Permissions. Reported by Tech Division (@taiphung) - Mobifone Digital Payment on 2026-06-02

[N/A][519243927] Medium CVE-2026-17851: Side-channel information leakage in Autofill. Reported by Google on 2026-06-02

[N/A][519348818] Medium CVE-2026-17852: Inappropriate implementation in Media Router. Reported by Google on 2026-06-03

[TBD][519472272] Medium CVE-2026-17853: Inappropriate implementation in DevTools. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-06-03

[N/A][519500882] Medium CVE-2026-17854: Insufficient policy enforcement in WebMCP. Reported by Google on 2026-06-03

[N/A][519982572] Medium CVE-2026-17855: Race in DevTools. Reported by Google on 2026-06-04

[N/A][519991751] Medium CVE-2026-17856: Inappropriate implementation in Network. Reported by Google on 2026-06-04

[N/A][520186620] Medium CVE-2026-17857: Inappropriate implementation in Network. Reported by Google on 2026-06-05

[N/A][520191468] Medium CVE-2026-17858: Uninitialized Use in WebNN. Reported by Google on 2026-06-05

[N/A][520196753] Medium CVE-2026-17859: Side-channel information leakage in Favicons. Reported by Google on 2026-06-05

[N/A][520407381] Medium CVE-2026-17860: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-06-05

[N/A][520417861] Medium CVE-2026-17861: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-05

[N/A][520426287] Medium CVE-2026-17862: Use after free in Tracing. Reported by Google on 2026-06-05

[N/A][520468718] Medium CVE-2026-17863: Inappropriate implementation in Browser. Reported by Google on 2026-06-05

[N/A][520494861] Medium CVE-2026-17864: Inappropriate implementation in Updater. Reported by Google on 2026-06-05

[N/A][520516655] Medium CVE-2026-17865: Inappropriate implementation in Crypto. Reported by Google on 2026-06-05

[N/A][520525732] Medium CVE-2026-17866: Type Confusion in Tab. Reported by Google on 2026-06-05

[N/A][520527496] Medium CVE-2026-17867: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-06-05

[TBD][520743499] Medium CVE-2026-17868: Insufficient policy enforcement in USB. Reported by Ariel Simon on 2026-06-06

[N/A][521759269] Medium CVE-2026-17869: Out of bounds read in WebXR. Reported by Google on 2026-06-09

[N/A][521784856] Medium CVE-2026-17870: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-09

[N/A][521938924] Medium CVE-2026-17871: Inappropriate implementation in Passwords. Reported by Google on 2026-06-09

[N/A][521963740] Medium CVE-2026-17872: Cryptographic Flaw in WebAppInstalls. Reported by Google on 2026-06-09

[N/A][522074033] Medium CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-10

[N/A][522074154] Medium CVE-2026-17874: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-10

[N/A][522299155] Medium CVE-2026-17875: Use after free in PDFium. Reported by Google on 2026-06-10

[N/A][522425471] Medium CVE-2026-17876: Inappropriate implementation in Payments. Reported by Google on 2026-06-10

[N/A][522426086] Medium CVE-2026-17877: Inappropriate implementation in Chromoting. Reported by Google on 2026-06-10

[N/A][522781838] Medium CVE-2026-17878: Inappropriate implementation in CSS. Reported by Google on 2026-06-11

[N/A][522878450] Medium CVE-2026-17879: Inappropriate implementation in Autofill. Reported by Google on 2026-06-11

[N/A][523229759] Medium CVE-2026-17880: Inappropriate implementation in Autofill. Reported by Google on 2026-06-12

[N/A][523477987] Medium CVE-2026-17881: Use after free in WebXR. Reported by Google on 2026-06-13

[N/A][523637452] Medium CVE-2026-17882: Policy bypass in Extensions. Reported by Google on 2026-06-13

[N/A][523639090] Medium CVE-2026-17883: Inappropriate implementation in Headless. Reported by Google on 2026-06-13

[N/A][523692228] Medium CVE-2026-17884: Object lifecycle issue in WebRTC. Reported by Google on 2026-06-13

[N/A][523698038] Medium CVE-2026-17885: Inappropriate implementation in Paint. Reported by Google on 2026-06-13

[N/A][523715964] Medium CVE-2026-17886: Use after free in Enterprise. Reported by Google on 2026-06-14

[N/A][523717010] Medium CVE-2026-17887: Use after free in TabStrip. Reported by Google on 2026-06-14

[N/A][523720529] Medium CVE-2026-17888: Insufficient validation of untrusted input in WebUI. Reported by Google on 2026-06-14

[N/A][523735357] Medium CVE-2026-17889: Uninitialized Use in WebXR. Reported by Google on 2026-06-14

[N/A][524029061] Medium CVE-2026-17890: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-15

[N/A][524639223] Medium CVE-2026-17891: Use after free in ANGLE. Reported by Google on 2026-06-16

[N/A][524822998] Medium CVE-2026-17892: Inappropriate implementation in WebXR. Reported by Google on 2026-06-17

[N/A][524824730] Medium CVE-2026-17893: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-17

[N/A][524825209] Medium CVE-2026-17894: Use after free in Views. Reported by Google on 2026-06-17

[TBD][524931675] Medium CVE-2026-17895: Inappropriate implementation in DataTransfer. Reported by hongan@calif.io on 2026-06-17

[N/A][525331547] Medium CVE-2026-17896: Use after free in DevTools. Reported by Google on 2026-06-18

[TBD][527665262] Medium CVE-2026-17897: Inappropriate implementation in ORB. Reported by Sharkkcode on 2026-06-25

[$3000][506193577] Low CVE-2026-17898: Use after free in DevTools. Reported by Syn4pse on 2026-04-24

[$1000][375959766] Low CVE-2026-17899: Insufficient policy enforcement in DevTools. Reported by asnine on 2024-10-28

[N/A][496195854] Low CVE-2026-17900: Inappropriate implementation in Enterprise. Reported by Google on 2026-03-25

[N/A][496271098] Low CVE-2026-17901: Inappropriate implementation in Sharing. Reported by Google on 2026-03-25

[N/A][497251066] Low CVE-2026-17902: Inappropriate implementation in Editing. Reported by Google on 2026-03-28

[N/A][497277880] Low CVE-2026-17903: Insufficient policy enforcement in Chromecast. Reported by Google on 2026-03-28

[N/A][497337759] Low CVE-2026-17904: Insufficient policy enforcement in NFC. Reported by Google on 2026-03-29

[N/A][497366217] Low CVE-2026-17905: Inappropriate implementation in SurfaceCapture. Reported by Google on 2026-03-29

[N/A][497654761] Low CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth. Reported by Google on 2026-03-30

[N/A][497837927] Low CVE-2026-17907: Side-channel information leakage in Network. Reported by Google on 2026-03-30

[N/A][499062890] Low CVE-2026-17908: Insufficient validation of untrusted input in Printing. Reported by Google on 2026-04-02

[N/A][501693236] Low CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps. Reported by Google on 2026-04-11

[N/A][501749600] Low CVE-2026-17910: Insufficient policy enforcement in NFC. Reported by Google on 2026-04-11

[N/A][502505715] Low CVE-2026-17911: Insufficient policy enforcement in SVG. Reported by Google on 2026-04-14

[N/A][504202939] Low CVE-2026-17912: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19

[N/A][504209246] Low CVE-2026-17913: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19

[N/A][506377118] Low CVE-2026-17914: Side-channel information leakage in Skia. Reported by Google on 2026-04-25

[N/A][506390325] Low CVE-2026-17915: Inappropriate implementation in WebView. Reported by Google on 2026-04-25

[TBD][510808598] Low CVE-2026-17916: Insufficient policy enforcement in Settings. Reported by Itzik Chimino on 2026-05-07

[N/A][511816897] Low CVE-2026-17917: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-10

[N/A][513127137] Low CVE-2026-17918: Use after free in Sync. Reported by Google on 2026-05-14

[N/A][513291747] Low CVE-2026-17919: Insufficient policy enforcement in Enterprise. Reported by Google on 2026-05-14

[N/A][513413942] Low CVE-2026-17920: Use after free in V8. Reported by Google on 2026-05-15

[N/A][513503197] Low CVE-2026-17921: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-05-15

[N/A][513611659] Low CVE-2026-17922: Inappropriate implementation in Enterprise. Reported by Google on 2026-05-15

[N/A][513612928] Low CVE-2026-17923: Policy bypass in Enterprise. Reported by Google on 2026-05-15

[N/A][513714124] Low CVE-2026-17924: Use after free in DNS. Reported by Google on 2026-05-16

[N/A][513719671] Low CVE-2026-17925: Inappropriate implementation in Cast. Reported by Google on 2026-05-16

[N/A][513735900] Low CVE-2026-17926: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513754837] Low CVE-2026-17927: Insufficient policy enforcement in DevTools. Reported by Google on 2026-05-16

[N/A][513762372] Low CVE-2026-17928: Inappropriate implementation in DataTransfer. Reported by Google on 2026-05-16

[N/A][513768645] Low CVE-2026-17929: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513769158] Low CVE-2026-17930: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-16

[N/A][513781245] Low CVE-2026-17931: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513819157] Low CVE-2026-17932: Use after free in DataTransfer. Reported by Google on 2026-05-16

[N/A][513822044] Low CVE-2026-17933: Inappropriate implementation in DOMStorage. Reported by Google on 2026-05-16

[N/A][513838421] Low CVE-2026-17934: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513863267] Low CVE-2026-17935: Heap buffer overflow in Codecs. Reported by Google on 2026-05-16

[N/A][513864014] Low CVE-2026-17936: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513866380] Low CVE-2026-17937: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513989304] Low CVE-2026-17938: Inappropriate implementation in FullScreen. Reported by Google on 2026-05-17

[N/A][514060089] Low CVE-2026-17939: Inappropriate implementation in Passwords. Reported by Google on 2026-05-17

[N/A][514069440] Low CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture. Reported by Google on 2026-05-17

[N/A][514147906] Low CVE-2026-17941: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-18

[N/A][514406198] Low CVE-2026-17942: Side-channel information leakage in SVG. Reported by Google on 2026-05-18

[N/A][514424283] Low CVE-2026-17943: Inappropriate implementation in Parser. Reported by Google on 2026-05-18

[N/A][514510853] Low CVE-2026-17944: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-19

[N/A][514519203] Low CVE-2026-17945: Inappropriate implementation in Navigation. Reported by Google on 2026-05-19

[N/A][515437522] Low CVE-2026-17946: Uninitialized Use in Dawn. Reported by Google on 2026-05-21

[N/A][515438256] Low CVE-2026-17947: Use after free in WebSockets. Reported by Google on 2026-05-21

[N/A][516849257] Low CVE-2026-17948: Type Confusion in V8. Reported by Google on 2026-05-26

[N/A][517000034] Low CVE-2026-17949: Uninitialized Use in GPU. Reported by Google on 2026-05-27

[N/A][517063658] Low CVE-2026-17950: Policy bypass in Safebrowsing. Reported by Google on 2026-05-27

[N/A][517180511] Low CVE-2026-17951: Heap buffer overflow in WebRTC. Reported by Google on 2026-05-27

[N/A][517316174] Low CVE-2026-17952: Inappropriate implementation in V8. Reported by Google on 2026-05-28

[N/A][517335150] Low CVE-2026-17953: Insufficient policy enforcement in WebView. Reported by Google on 2026-05-28

[N/A][517383492] Low CVE-2026-17954: Policy bypass in MHTML. Reported by Google on 2026-05-28

[N/A][517385072] Low CVE-2026-17955: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-28

[N/A][517436171] Low CVE-2026-17956: Inappropriate implementation in Scheduling. Reported by Google on 2026-05-28

[N/A][517476342] Low CVE-2026-17957: Inappropriate implementation in CORS. Reported by Google on 2026-05-28

[N/A][517538206] Low CVE-2026-17958: Inappropriate implementation in Views. Reported by Google on 2026-05-28

[N/A][517607890] Low CVE-2026-17959: Inappropriate implementation in Network. Reported by Google on 2026-05-28

[N/A][517631680] Low CVE-2026-17960: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517700791] Low CVE-2026-17961: Inappropriate implementation in Session. Reported by Google on 2026-05-29

[N/A][517757268] Low CVE-2026-17962: Inappropriate implementation in Blink. Reported by Google on 2026-05-29

[N/A][517759257] Low CVE-2026-17963: Inappropriate implementation in SVG. Reported by Google on 2026-05-29

[N/A][518025103] Low CVE-2026-17964: Incorrect security UI in UI. Reported by Google on 2026-05-29

[N/A][518049812] Low CVE-2026-17965: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518058990] Low CVE-2026-17966: Inappropriate implementation in Views. Reported by Google on 2026-05-30

[N/A][518243858] Low CVE-2026-17967: Use after free in Chrome for iOS. Reported by Google on 2026-05-30

[N/A][518337516] Low CVE-2026-17968: Uninitialized Use in WebXR. Reported by Google on 2026-05-31

[N/A][518812295] Low CVE-2026-17969: Inappropriate implementation in Passwords. Reported by Google on 2026-06-01

[N/A][518814464] Low CVE-2026-17970: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-01

[N/A][518815075] Low CVE-2026-17971: Inappropriate implementation in Frame. Reported by Google on 2026-06-01

[N/A][519202895] Low CVE-2026-17972: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-02

[N/A][519230894] Low CVE-2026-17973: Inappropriate implementation in Views. Reported by Google on 2026-06-02

[N/A][519232592] Low CVE-2026-17974: Insufficient policy enforcement in DevTools. Reported by Google on 2026-06-02

[N/A][519233776] Low CVE-2026-17975: Inappropriate implementation in IME. Reported by Google on 2026-06-02

[N/A][519455164] Low CVE-2026-17976: Policy bypass in Extensions. Reported by Google on 2026-06-03

[N/A][519603552] Low CVE-2026-17977: Policy bypass in CSS. Reported by Google on 2026-06-03

[N/A][519610845] Low CVE-2026-17978: Side-channel information leakage in WebCodecs. Reported by Google on 2026-06-03

[N/A][519664497] Low CVE-2026-17979: Race in V8. Reported by Google on 2026-06-04

[N/A][519710361] Low CVE-2026-17980: Inappropriate implementation in UI. Reported by Google on 2026-06-03

[N/A][519719512] Low CVE-2026-17981: Inappropriate implementation in Blink. Reported by Google on 2026-06-03

[N/A][519735808] Low CVE-2026-17982: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-04

[N/A][519744561] Low CVE-2026-17983: Incorrect security UI in Global Media Controls. Reported by Google on 2026-06-04

[N/A][519978460] Low CVE-2026-17984: Inappropriate implementation in Browser. Reported by Google on 2026-06-04

[N/A][519981430] Low CVE-2026-17985: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-04

[N/A][519981896] Low CVE-2026-17986: Insufficient policy enforcement in Bluetooth. Reported by Google on 2026-06-04

[N/A][519988071] Low CVE-2026-17987: Insufficient validation of untrusted input in Notifications. Reported by Google on 2026-06-04

[N/A][520005624] Low CVE-2026-17988: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-06-04

[N/A][520017306] Low CVE-2026-17989: Type Confusion in V8. Reported by Google on 2026-06-04

[N/A][520018012] Low CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn. Reported by Google on 2026-06-04

[N/A][520110535] Low CVE-2026-17991: Insufficient validation of untrusted input in AI. Reported by Google on 2026-06-04

[N/A][520506316] Low CVE-2026-17992: Uninitialized Use in Skia. Reported by Google on 2026-06-05

[N/A][520532191] Low CVE-2026-17993: Race in Updater. Reported by Google on 2026-06-05

[N/A][520663771] Low CVE-2026-17994: Inappropriate implementation in Media. Reported by Google on 2026-06-06

[TBD][520972775] Low CVE-2026-17995: Out of bounds read in Dawn. Reported by sm1ee, ksw9722 on 2026-06-07

[N/A][521473427] Low CVE-2026-17996: Inappropriate implementation in Browser. Reported by Google on 2026-06-08

[N/A][521476960] Low CVE-2026-17997: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08

[N/A][521601450] Low CVE-2026-17998: Incorrect security UI in Extensions. Reported by Google on 2026-06-09

[N/A][521615681] Low CVE-2026-17999: Incorrect security UI in PictureInPicture. Reported by Google on 2026-06-09

[N/A][521623907] Low CVE-2026-18000: Insufficient policy enforcement in USB. Reported by Google on 2026-06-09

[N/A][521757779] Low CVE-2026-18001: Inappropriate implementation in WebGL. Reported by Google on 2026-06-09

[N/A][521864362] Low CVE-2026-18002: Insufficient validation of untrusted input in Google Lens. Reported by Google on 2026-06-09

[N/A][521934304] Low CVE-2026-18003: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-09

[N/A][522280805] Low CVE-2026-18004: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-10

[N/A][522300211] Low CVE-2026-18005: Inappropriate implementation in WebXR. Reported by Google on 2026-06-10

[N/A][522396262] Low CVE-2026-18006: Inappropriate implementation in Google Lens. Reported by Google on 2026-06-10

[N/A][522404101] Low CVE-2026-18007: Inappropriate implementation in Input. Reported by Google on 2026-06-10

[N/A][522412676] Low CVE-2026-18008: Inappropriate implementation in Settings. Reported by Google on 2026-06-10

[N/A][522419718] Low CVE-2026-18009: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-10

[N/A][522419819] Low CVE-2026-18010: Inappropriate implementation in Passwords. Reported by Google on 2026-06-10

[N/A][522479633] Low CVE-2026-18011: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-11

[N/A][522938824] Low CVE-2026-18012: Use after free in PDFium. Reported by Google on 2026-06-11

[N/A][523245998] Low CVE-2026-18013: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-12

[N/A][523248021] Low CVE-2026-18014: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-12

[N/A][523698428] Low CVE-2026-18015: Inappropriate implementation in Tint. Reported by Google on 2026-06-13

[N/A][523708527] Low CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-13

[N/A][523731236] Low CVE-2026-18017: Use after free in Dawn. Reported by Google on 2026-06-14

[N/A][524467747] Low CVE-2026-18018: Inappropriate implementation in Updater. Reported by Google on 2026-06-16

[N/A][525691898] Low CVE-2026-18019: Side-channel information leakage in Media. Reported by Google on 2026-06-19

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Krishna Govind

Google Chrome


  •  

Extended Stable Updates for Desktop

28 Juli 2026 om 22:29

Β The Extended Stable channel has been updated to 150.0.7871.212 for Windows and Mac which will roll out over the coming days/weeks.


A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Krishna Govind
Google Chrome
  •  

Stable Channel Update for Desktop

23 Juli 2026 om 23:35

The Stable channel has been updated to 150.0.7871.186/.187 for Windows and Mac and 150.0.7871.186 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log


Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 4 security fixes. Please see the Chrome Security Page for more information.


[N/A][518237034] High CVE-2026-16807: Out of bounds write in Codecs. Reported by Google on 2026-05-30

[N/A][522064153] High CVE-2026-16806: Use after free in WebMCP. Reported by Google on 2026-06-10

[N/A][523292588] High CVE-2026-16805: Use after free in Blink. Reported by Google on 2026-06-12

[N/A][524721670] High CVE-2026-16804: Use after free in Input. Reported by Google on 2026-06-16


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.



Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome


  •  

Early Stable Update for Desktop

22 Juli 2026 om 18:19

Β The Stable channel has been updated to 151.0.7922.47/.48 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

21 Juli 2026 om 23:59

The Stable channel has been updated to 150.0.7871.181/.182 for Windows and Mac and 150.0.7871.181 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log


Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 12 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.


[$500][527930356] High CVE-2026-16420: Type Confusion in WebAudio. Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt on 2026-06-26

[$500][528276487] High CVE-2026-16421: Inappropriate implementation in WebAudio. Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt on 2026-06-26

[N/A][517359779] High CVE-2026-16413: Out of bounds write in ANGLE. Reported by Google on 2026-05-28

[N/A][517651910] High CVE-2026-16414: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-05-28

[N/A][519244446] High CVE-2026-16415: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-06-02

[N/A][520172356] High CVE-2026-16416: Integer overflow in Chromecast. Reported by Google on 2026-06-05

[N/A][521491024] High CVE-2026-16417: Uninitialized Use in Skia. Reported by Google on 2026-06-08

[N/A][522125255] High CVE-2026-16418: Stack buffer overflow in V8. Reported by Google on 2026-06-10

[N/A][523435970] High CVE-2026-16419: Out of bounds read and write in ANGLE. Reported by Google on 2026-06-13

[N/A][533515002] High CVE-2026-16422: Insufficient validation of untrusted input in Certificate. Reported by Google on 2026-07-10

[N/A][534582496] High CVE-2026-16423: Use after free in UI. Reported by Google on 2026-07-14

[N/A][534858939] High CVE-2026-16424: Use after free in GPU. Reported by Google on 2026-07-14


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome


  •  

Stable Channel Update for Desktop

17 Juli 2026 om 01:30

The Stable channel has been updated to 150.0.7871.128/.129 for Windows and Mac and 150.0.7871.128 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 7 security fixes. Please see the Chrome Security Page for more information.

[N/A][516987782] Critical CVE-2026-15899: Use after free in CameraCapture. Reported by Google on 2026-05-27

[N/A][523750584] Critical CVE-2026-15900: Use after free in GPU. Reported by Google on 2026-06-14

[N/A][533446300] Critical CVE-2026-15901: Use after free in Network. Reported by Google on 2026-07-10

[N/A][522436154] High CVE-2026-15902: Use after free in Cast. Reported by Google on 2026-06-10

[TBD][531503216] High CVE-2026-15903: Out of bounds read and write in V8. Reported by OpenAI Codex Security (amyb) on 2026-07-06

[N/A][532925350] High CVE-2026-15904: Use after free in Ozone. Reported by Google on 2026-07-09

[N/A][532970574] High CVE-2026-15905: Use after free in Aura. Reported by Google on 2026-07-09

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Early Stable Update for Desktop

15 Juli 2026 om 22:54

The Stable channel has been updated to 151.0.7922.34/.35 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

14 Juli 2026 om 20:58

The Stable channel has been updated to 150.0.7871.124/.125 for Windows and Mac and 150.0.7871.124 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 15 security fixes. Please see the Chrome Security Page for more information.

[N/A][517100492] Critical CVE-2026-15764: Use after free in Ozone. Reported by Google on 2026-05-27

[N/A][518007484] Critical CVE-2026-15765: Use after free in Ozone. Reported by Google on 2026-05-29

[N/A][514010477] High CVE-2026-15766: Uninitialized Use in Skia. Reported by Google on 2026-05-17

[N/A][514748734] High CVE-2026-15767: Heap buffer overflow in libyuv. Reported by Google on 2026-05-19

[N/A][517931625] High CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas. Reported by Google on 2026-05-29

[N/A][519731111] High CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming. Reported by Google on 2026-06-03

[N/A][524792614] High CVE-2026-15770: Uninitialized Use in V8. Reported by Google on 2026-06-17

[N/A][525177160] High CVE-2026-15771: Insufficient validation of untrusted input in Media. Reported by Google on 2026-06-18

[N/A][525317502] High CVE-2026-15772: Use after free in GPU. Reported by Google on 2026-06-18

[TBD][527676561] High CVE-2026-15773: Use after free in Core. Reported by xinchaotian of Microsoft on 2026-06-25

[N/A][530646115] High CVE-2026-15774: Use after free in Skia. Reported by Google on 2026-07-03

[TBD][531319201] High CVE-2026-15775: Insufficient policy enforcement in V8. Reported by wang1r923096443@gmail.com on 2026-07-05

[TBD][532595489] High CVE-2026-15776: Type Confusion in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-07-08

[N/A][532929679] High CVE-2026-15777: Use after free in UI. Reported by Google on 2026-07-09

[N/A][513795122] Medium CVE-2026-15778: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-05-16


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

9 Juli 2026 om 00:31

The Stable channel has been updated to 150.0.7871.114/.115 for Windows and Mac and 150.0.7871.114 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 27 security fixes. Please see the Chrome Security Page for more information.

[N/A][518006275] Critical CVE-2026-15112: Use after free in Ozone. Reported by Google on 2026-05-29

[N/A][524045160] Critical CVE-2026-15129: Use after free in Views. Reported by Google on 2026-06-15

[$500][527385397] High CVE-2026-15132: Uninitialized Use in V8. Reported by Pierre Langlois from Arm on 2026-06-24

[$500][527406824] High CVE-2026-15133: Use after free in InterestGroups. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-06-24

[N/A][515443146] High CVE-2026-15108: Integer overflow in Extensions API. Reported by Google on 2026-05-21

[N/A][516899138] High CVE-2026-15109: Uninitialized Use in ANGLE. Reported by Google on 2026-05-26

[N/A][516948486] High CVE-2026-15110: Use after free in Extensions. Reported by Google on 2026-05-27

[N/A][517508651] High CVE-2026-15111: Use after free in Views. Reported by Google on 2026-05-28

[N/A][520540744] High CVE-2026-15113: Use after free in Autofill. Reported by Google on 2026-06-05

[N/A][520565945] High CVE-2026-15114: Out of bounds read and write in Codecs. Reported by Google on 2026-06-06

[N/A][520576676] High CVE-2026-15115: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google on 2026-06-06

[N/A][522092013] High CVE-2026-15116: Use after free in Actor. Reported by Google on 2026-06-10

[N/A][522568496] High CVE-2026-15117: Use after free in Payments. Reported by Google on 2026-06-11

[N/A][523238265] High CVE-2026-15118: Use after free in Input. Reported by Google on 2026-06-12

[N/A][523505418] High CVE-2026-15119: Inappropriate implementation in GetUserMedia. Reported by Google on 2026-06-13

[N/A][523609602] High CVE-2026-15120: Use after free in Core. Reported by Google on 2026-06-13

[N/A][523712556] High CVE-2026-15121: Use after free in WebRTC. Reported by Google on 2026-06-14

[N/A][523717219] High CVE-2026-15122: Insufficient validation of untrusted input in Codecs. Reported by Google on 2026-06-14

[N/A][523729553] High CVE-2026-15123: Insufficient data validation in DOM. Reported by Google on 2026-06-14

[N/A][523735038] High CVE-2026-15124: Insufficient policy enforcement in Passwords. Reported by Google on 2026-06-14

[N/A][523737685] High CVE-2026-15125: Inappropriate implementation in Forms. Reported by Google on 2026-06-14

[N/A][523748081] High CVE-2026-15126: Use after free in Forms. Reported by Google on 2026-06-14

[N/A][523752265] High CVE-2026-15127: Inappropriate implementation in WebGL. Reported by Google on 2026-06-14

[N/A][523756329] High CVE-2026-15128: Inappropriate implementation in Forms. Reported by Google on 2026-06-14

[N/A][526541544] High CVE-2026-15130: Insufficient policy enforcement in Navigation. Reported by Google on 2026-06-22

[$2000][503553615] Medium CVE-2026-15107: Use after free in IndexedDB. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab on 2026-04-17

[N/A][526542464] Medium CVE-2026-15131: Insufficient data validation in Navigation. Reported by Google on 2026-06-22


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

7 Juli 2026 om 19:38

Β The Stable channel has been updated to 150.0.7871.100/.101 for Windows and Mac andΒ 150.0.7871.100Β for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

2 Juli 2026 om 00:27

The Chrome team is delighted to announce the promotion of Chrome 150 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.

Chrome 150.0.7871.46 (Linux)Β 150.0.7871.46/.47Β Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 150.

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 433 security fixes. Please see the Chrome Security Page for more information.

[N/A][506558270] Critical CVE-2026-13774: Use after free in Extensions. Reported by Google on 2026-04-26

[N/A][511766407] Critical CVE-2026-13775: Use after free in GPU. Reported by Google on 2026-05-10

[N/A][512995785] Critical CVE-2026-14398: Use after free in ANGLE. Reported by Google on 2026-05-13

[N/A][513012139] Critical CVE-2026-13776: Type Confusion in Dawn. Reported by Google on 2026-05-14

[N/A][513128566] Critical CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb. Reported by Google on 2026-05-14

[N/A][513167952] Critical CVE-2026-13778: Use after free in WebUSB. Reported by Google on 2026-05-14

[N/A][513222854] Critical CVE-2026-13779: Use after free in Chromoting. Reported by Google on 2026-05-14

[N/A][514769383] Critical CVE-2026-13780: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-19

[N/A][516457532] Critical CVE-2026-13781: Insufficient validation of untrusted input in Skia. Reported by Google on 2026-05-25

[N/A][516649133] Critical CVE-2026-14417: Use after free in Dawn. Reported by Google on 2026-05-26

[N/A][516683433] Critical CVE-2026-13782: Use after free in Browser. Reported by Google on 2026-05-26

[N/A][516962178] Critical CVE-2026-13783: Use after free in Views. Reported by Google on 2026-05-27

[N/A][516962715] Critical CVE-2026-13784: Use after free in Views. Reported by Google on 2026-05-27

[N/A][516981393] Critical CVE-2026-14419: Use after free in Skia. Reported by Google on 2026-05-27

[N/A][517021684] Critical CVE-2026-13785: Use after free in Bluetooth. Reported by Google on 2026-05-27

[N/A][517031505] Critical CVE-2026-14420: Out of bounds read and write in Dawn. Reported by Google on 2026-05-27

[N/A][518007821] Critical CVE-2026-13786: Use after free in Ozone. Reported by Google on 2026-05-29

[N/A][520113415] Critical CVE-2026-14427: Heap buffer overflow in Skia. Reported by Google on 2026-06-04

[N/A][522919313] Critical CVE-2026-13787: Use after free in Chromoting. Reported by Google on 2026-06-11

[N/A][523119897] Critical CVE-2026-13788: Use after free in Fullscreen. Reported by Google on 2026-06-12

[$250000][492218546] High CVE-2026-14382: Insufficient validation of untrusted input in ANGLE. Reported by anonymous on 2026-03-13

[$10000][457771782] High CVE-2026-13790: Side-channel information leakage in Scroll. Reported by Vsevolod Kokorin (Slonser) of Solidlab and Jorian Woltjer on 2025-11-04

[$10000][499006005] High CVE-2026-14385: Heap buffer overflow in ANGLE. Reported by Thomas Guillem <thomas@gllm.fr> on 2026-04-03

[$10000][503850012] High CVE-2026-13791: Insufficient validation of untrusted input in Downloads. Reported by Ron Masas (Imperva) on 2026-04-17

[$4000][496012368] High CVE-2026-13792: Use after free in Touchbar. Reported by Weipeng Jiang (@Krace) of VRI on 2026-03-25

[$3000][510829679] High CVE-2026-13793: Insufficient policy enforcement in SVG. Reported by pakhunov.anton.n@gmail.com on 2026-05-07

[$2500][508265321] High CVE-2026-14392: Out of bounds write in Tint. Reported by FastPL Group, Imperial College London on 2026-04-30

[$2500][513893425] High CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls. Reported by Daniel RodrΓ­guez on 2026-05-16

[$2500][517225032] High CVE-2026-14422: Out of bounds read and write in Tint. Reported by Michal Andryskowski on 2026-05-28

[$2000][476591032] High CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS. Reported by maitai on 2026-01-17

[$1000][517981277] High CVE-2026-14426: Use after free in V8. Reported by ywatanabee on 2026-05-30

[N/A][491894115] High CVE-2026-13796: Integer overflow in Chromecast. Reported by Google on 2026-03-11

[N/A][499025645] High CVE-2026-13797: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-04-02

[N/A][499047960] High CVE-2026-14386: Out of bounds read in ANGLE. Reported by Google on 2026-04-02

[N/A][499048914] High CVE-2026-13798: Heap buffer overflow in Chromecast. Reported by Google on 2026-04-02

[N/A][499252371] High CVE-2026-13799: Use after free in QUIC. Reported by Google on 2026-04-03

[N/A][500108770] High CVE-2026-13800: Inappropriate implementation in Updater. Reported by Google on 2026-04-06

[N/A][500587568] High CVE-2026-13801: Integer overflow in Chromecast. Reported by Google on 2026-04-08

[N/A][501623322] High CVE-2026-13802: Use after free in Views. Reported by Google on 2026-04-11

[N/A][501669642] High CVE-2026-13803: Type Confusion in Chrome Tabs. Reported by Google on 2026-04-11

[N/A][501873032] High CVE-2026-13804: Use after free in Chromecast. Reported by Google on 2026-04-12

[N/A][502282040] High CVE-2026-13805: Use after free in GFX. Reported by Google on 2026-04-13

[N/A][503054174] High CVE-2026-14390: Use after free in ANGLE. Reported by Google on 2026-04-15

[N/A][503333798] High CVE-2026-13806: Insufficient validation of untrusted input in Accessibility. Reported by Google on 2026-04-16

[N/A][504194494] High CVE-2026-13807: Use after free in Import. Reported by Google on 2026-04-19

[N/A][504221510] High CVE-2026-13808: Insufficient data validation in Chrome for iOS. Reported by Google on 2026-04-19

[N/A][504222227] High CVE-2026-13809: Side-channel information leakage in Safe Browsing. Reported by Google on 2026-04-19

[TBD][504600482] High CVE-2026-13810: Inappropriate implementation in Input. Reported by dilipsc03@gmail.com on 2026-04-20

[N/A][506149253] High CVE-2026-13811: Use after free in IME. Reported by Google on 2026-04-24

[N/A][508293203] High CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][508462149] High CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-01

[N/A][511712766] High CVE-2026-13814: Use after free in Views. Reported by Google on 2026-05-10

[N/A][511722207] High CVE-2026-13815: Use after free in Blink. Reported by Google on 2026-05-10

[N/A][511735715] High CVE-2026-13816: Insufficient validation of untrusted input in File Input. Reported by Google on 2026-05-10

[N/A][511737097] High CVE-2026-14396: Out of bounds read in ANGLE. Reported by Google on 2026-05-10

[N/A][511739631] High CVE-2026-13817: Insufficient validation of untrusted input in Glic. Reported by Google on 2026-05-10

[N/A][511823182] High CVE-2026-13818: Inappropriate implementation in Passwords. Reported by Google on 2026-05-10

[N/A][512962749] High CVE-2026-13819: Out of bounds read in ANGLE. Reported by Google on 2026-05-13

[N/A][512986879] High CVE-2026-13820: Out of bounds read in Skia. Reported by Google on 2026-05-13

[N/A][513010645] High CVE-2026-14400: Out of bounds write in ANGLE. Reported by Google on 2026-05-14

[N/A][513048822] High CVE-2026-14401: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-14

[N/A][513051340] High CVE-2026-14402: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14

[N/A][513142445] High CVE-2026-13821: Use after free in Canvas. Reported by Google on 2026-05-14

[N/A][513148038] High CVE-2026-13822: Inappropriate implementation in Extensions. Reported by Google on 2026-05-14

[N/A][513163011] High CVE-2026-13823: Use after free in Glic. Reported by Google on 2026-05-14

[N/A][513177497] High CVE-2026-13824: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-14

[N/A][513209610] High CVE-2026-13825: Uninitialized Use in Dawn. Reported by Google on 2026-05-14

[N/A][513237800] High CVE-2026-13826: Inappropriate implementation in Autofill. Reported by Google on 2026-05-14

[N/A][513371963] High CVE-2026-13827: Use after free in Updater. Reported by Google on 2026-05-15

[N/A][513399832] High CVE-2026-13828: Inappropriate implementation in Enterprise. Reported by Google on 2026-05-15

[N/A][513490996] High CVE-2026-13829: Insufficient validation of untrusted input in Settings. Reported by Google on 2026-05-15

[N/A][513727494] High CVE-2026-13830: Use after free in Chromoting. Reported by Google on 2026-05-16

[N/A][513781328] High CVE-2026-13831: Use after free in GPU. Reported by Google on 2026-05-16

[N/A][513822378] High CVE-2026-13832: Use after free in Headless. Reported by Google on 2026-05-16

[N/A][513919827] High CVE-2026-14411: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-17

[N/A][513920082] High CVE-2026-13833: Uninitialized Use in ANGLE. Reported by Google on 2026-05-17

[N/A][513920834] High CVE-2026-14412: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-17

[N/A][513922055] High CVE-2026-14413: Uninitialized Use in ANGLE. Reported by Google on 2026-05-17

[N/A][513925114] High CVE-2026-13834: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-17

[N/A][514338102] High CVE-2026-13835: Inappropriate implementation in XML. Reported by Google on 2026-05-18

[N/A][514420555] High CVE-2026-13836: Inappropriate implementation in CSS. Reported by Google on 2026-05-18

[N/A][514429130] High CVE-2026-13837: Inappropriate implementation in CSS. Reported by Google on 2026-05-18

[N/A][514445398] High CVE-2026-13838: Inappropriate implementation in CSS. Reported by Google on 2026-05-18

[N/A][514449396] High CVE-2026-13839: Inappropriate implementation in CSS. Reported by Google on 2026-05-18

[TBD][514609778] High CVE-2026-13840: Insufficient policy enforcement in Canvas. Reported by Binglin Song on 2026-05-19

[N/A][515467789] High CVE-2026-13841: Integer overflow in Skia. Reported by Google on 2026-05-21

[TBD][516836297] High CVE-2026-13842: Incorrect security UI in Chrome for iOS. Reported by Azza Tegar Naufal Ataullah on 2026-05-26

[N/A][516865345] High CVE-2026-14418: Uninitialized Use in ANGLE. Reported by Google on 2026-05-26

[N/A][516869032] High CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-26

[N/A][516926115] High CVE-2026-13844: Use after free in Updater. Reported by Google on 2026-05-27

[N/A][516936863] High CVE-2026-13845: Use after free in DOM. Reported by Google on 2026-05-27

[N/A][516999424] High CVE-2026-13846: Use after free in USB. Reported by Google on 2026-05-27

[N/A][517073397] High CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-27

[N/A][517345069] High CVE-2026-13848: Use after free in Forms. Reported by Google on 2026-05-28

[N/A][517351411] High CVE-2026-13849: Insufficient validation of untrusted input in Chromoting. Reported by Google on 2026-05-28

[N/A][517522769] High CVE-2026-14423: Type Confusion in Tint. Reported by Google on 2026-05-28

[N/A][517610676] High CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-28

[N/A][517692772] High CVE-2026-14424: Use after free in Dawn. Reported by Google on 2026-05-29

[N/A][517935753] High CVE-2026-14425: Use after free in ANGLE. Reported by Google on 2026-05-29

[N/A][519692255] High CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google on 2026-06-03

[N/A][520180257] High CVE-2026-14428: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-06-05

[N/A][520571816] High CVE-2026-14429: Insufficient validation of untrusted input in Skia. Reported by Google on 2026-06-06

[N/A][522126182] High CVE-2026-14430: Integer overflow in V8. Reported by Google on 2026-06-10

[N/A][522560124] High CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google on 2026-06-11

[N/A][523224019] High CVE-2026-13853: Use after free in Journeys. Reported by Google on 2026-06-12

[N/A][523690961] High CVE-2026-13854: Use after free in Ozone. Reported by Google on 2026-06-13

[TBD][523884658] High CVE-2026-14431: Type Confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-06-15

[N/A][524395469] High CVE-2026-13855: Use after free in Ozone. Reported by Google on 2026-06-16

[$8000][508092634] Medium CVE-2026-13856: Insufficient validation of untrusted input in Speech. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-30

[$5000][479203484] Medium CVE-2026-13857: Inappropriate implementation in Geometry. Reported by Luan Herrera (@lbherrera_) on 2026-01-27

[$3000][507090179] Medium CVE-2026-13858: Out of bounds read in FFmpeg. Reported by Wongi Lee (@_qwerty_po) of Theori with Xint Code, Jungwoo Lee (@physicube) on 2026-04-27

[$2000][484756087] Medium CVE-2026-13859: Inappropriate implementation in ANGLE. Reported by Jason Villaluna on 2026-02-15

[$2000][506212452] Medium CVE-2026-14391: Integer overflow in ANGLE. Reported by Quac Tran on 2026-04-24

[$1000][417052041] Medium CVE-2026-13860: Incorrect security UI in Autofill. Reported by Khalil Zhani on 2025-05-12

[$1000][513631768] Medium CVE-2026-14408: Uninitialized Use in Dawn. Reported by Chrovus on 2026-05-16

[TBD][407283320] Medium CVE-2026-14381: Incorrect security UI in WebAppInstalls. Reported by Hafiizh on 2025-03-30

[N/A][492410546] Medium CVE-2026-14383: Inappropriate implementation in V8. Reported by Google on 2026-03-13

[N/A][495456765] Medium CVE-2026-13861: Use after free in Core. Reported by Google on 2026-03-23

[N/A][495897416] Medium CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-03-24

[N/A][496012495] Medium CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs. Reported by Google on 2026-03-25

[N/A][496399913] Medium CVE-2026-13864: Insufficient policy enforcement in WebHID. Reported by Google on 2026-03-26

[N/A][497090912] Medium CVE-2026-13865: Insufficient validation of untrusted input in Enterprise. Reported by Google on 2026-03-28

[N/A][497207698] Medium CVE-2026-13866: Insufficient validation of untrusted input in Input. Reported by Google on 2026-03-28

[N/A][497345177] Medium CVE-2026-13867: Inappropriate implementation in Geolocation. Reported by Google on 2026-03-29

[N/A][497453475] Medium CVE-2026-13868: Inappropriate implementation in Network. Reported by Google on 2026-03-29

[N/A][497543485] Medium CVE-2026-14384: Out of bounds read in ANGLE. Reported by Google on 2026-03-29

[N/A][497610642] Medium CVE-2026-13869: Use after free in Device. Reported by Google on 2026-03-30

[N/A][497634837] Medium CVE-2026-13870: Use after free in WebView. Reported by Google on 2026-03-30

[N/A][497961376] Medium CVE-2026-13871: Insufficient data validation in GuestView. Reported by Google on 2026-03-30

[N/A][497977983] Medium CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google on 2026-03-31

[N/A][498085466] Medium CVE-2026-13873: Out of bounds memory access in Layout. Reported by Google on 2026-03-31

[N/A][498411773] Medium CVE-2026-13874: Inappropriate implementation in DataTransfer. Reported by Google on 2026-04-01

[N/A][498721671] Medium CVE-2026-13875: Insufficient validation of untrusted input in GPU. Reported by Google on 2026-04-01

[N/A][498722200] Medium CVE-2026-13876: Inappropriate implementation in Network. Reported by Google on 2026-04-01

[N/A][498820206] Medium CVE-2026-13877: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-04-02

[N/A][499007266] Medium CVE-2026-13878: Use after free in Bluetooth. Reported by Google on 2026-04-02

[N/A][499022239] Medium CVE-2026-13879: Use after free in Bluetooth. Reported by Google on 2026-04-02

[N/A][499025880] Medium CVE-2026-13880: Use after free in USB. Reported by Google on 2026-04-02

[N/A][499100491] Medium CVE-2026-13881: Insufficient data validation in WebAppInstalls. Reported by Google on 2026-04-03

[N/A][499162550] Medium CVE-2026-13882: Inappropriate implementation in USB. Reported by Google on 2026-04-03

[N/A][500030250] Medium CVE-2026-13883: Type Confusion in ANGLE. Reported by Google on 2026-04-06

[N/A][500077014] Medium CVE-2026-13884: Heap buffer overflow in Chromecast. Reported by Google on 2026-04-06

[N/A][500305404] Medium CVE-2026-14387: Integer overflow in Skia. Reported by Google on 2026-04-07

[N/A][500474409] Medium CVE-2026-13885: Use after free in Skia. Reported by Google on 2026-04-07

[N/A][500475136] Medium CVE-2026-13886: Policy bypass in Isolated Web Apps. Reported by Google on 2026-04-07

[N/A][500476886] Medium CVE-2026-14388: Out of bounds read in ANGLE. Reported by Google on 2026-04-07

[N/A][500505046] Medium CVE-2026-14389: Integer overflow in Skia. Reported by Google on 2026-04-08

[N/A][500508524] Medium CVE-2026-13887: Insufficient policy enforcement in NFC. Reported by Google on 2026-04-08

[N/A][500566906] Medium CVE-2026-13888: Use after free in Extensions. Reported by Google on 2026-04-08

[N/A][500588580] Medium CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication. Reported by Google on 2026-04-08

[N/A][500601345] Medium CVE-2026-13890: Out of bounds read in Chromecast. Reported by Google on 2026-04-08

[N/A][501631475] Medium CVE-2026-13891: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-04-11

[N/A][501674841] Medium CVE-2026-13892: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-11

[N/A][501729582] Medium CVE-2026-13893: Insufficient validation of untrusted input in WebUI. Reported by Google on 2026-04-11

[N/A][501741117] Medium CVE-2026-13894: Insufficient policy enforcement in Network. Reported by Google on 2026-04-11

[N/A][501770542] Medium CVE-2026-13895: Inappropriate implementation in Autofill. Reported by Google on 2026-04-12

[N/A][501820076] Medium CVE-2026-13896: Insufficient policy enforcement in Glic. Reported by Google on 2026-04-12

[N/A][501877896] Medium CVE-2026-13897: Insufficient policy enforcement in Chromecast. Reported by Google on 2026-04-12

[N/A][501925480] Medium CVE-2026-13898: Use after free in Cast Receiver. Reported by Google on 2026-04-12

[N/A][502109002] Medium CVE-2026-13899: Use after free in HTML. Reported by Google on 2026-04-13

[N/A][502374993] Medium CVE-2026-13900: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-04-14

[N/A][503585173] Medium CVE-2026-13901: Insufficient validation of untrusted input in Serial. Reported by Google on 2026-04-17

[N/A][503725717] Medium CVE-2026-13902: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-17

[N/A][503912196] Medium CVE-2026-13903: Insufficient policy enforcement in Bluetooth. Reported by Google on 2026-04-18

[N/A][504185807] Medium CVE-2026-13904: Incorrect security UI in Safe Browsing. Reported by Google on 2026-04-19

[N/A][504192688] Medium CVE-2026-13905: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-04-19

[N/A][504613867] Medium CVE-2026-13906: Out of bounds read in Codecs. Reported by Google on 2026-04-20

[N/A][505156685] Medium CVE-2026-13907: Inappropriate implementation in iOSWeb. Reported by Google on 2026-04-22

[N/A][505242189] Medium CVE-2026-13908: Insufficient validation of untrusted input in Omnibox. Reported by Google on 2026-04-22

[N/A][505933538] Medium CVE-2026-13909: Insufficient policy enforcement in DevTools. Reported by Google on 2026-04-24

[N/A][507231605] Medium CVE-2026-13910: Insufficient policy enforcement in WebXR. Reported by Google on 2026-04-28

[N/A][507239830] Medium CVE-2026-13911: Insufficient data validation in Spellcheck. Reported by Google on 2026-04-28

[N/A][508259433] Medium CVE-2026-13912: Incorrect security UI in Safe Browsing. Reported by Google on 2026-04-30

[N/A][508260619] Medium CVE-2026-13913: Insufficient policy enforcement in Autofill. Reported by Google on 2026-04-30

[N/A][508273690] Medium CVE-2026-13914: Inappropriate implementation in Passwords. Reported by Google on 2026-04-30

[N/A][508275293] Medium CVE-2026-13915: Use after free in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][508283108] Medium CVE-2026-13916: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][508286935] Medium CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-04-30

[N/A][509712284] Medium CVE-2026-13918: Use after free in Chrome for iOS. Reported by Google on 2026-05-05

[N/A][511249430] Medium CVE-2026-13919: Insufficient data validation in Extensions. Reported by Google on 2026-05-08

[N/A][511255112] Medium CVE-2026-14393: Use after free in V8. Reported by Google on 2026-05-08

[N/A][511722559] Medium CVE-2026-13920: Insufficient validation of untrusted input in Media. Reported by Google on 2026-05-10

[N/A][511738175] Medium CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials. Reported by Google on 2026-05-10

[N/A][511748106] Medium CVE-2026-13922: Side-channel information leakage in Paint. Reported by Google on 2026-05-10

[N/A][511772034] Medium CVE-2026-13923: Uninitialized Use in GPU. Reported by Google on 2026-05-10

[N/A][511772608] Medium CVE-2026-14397: Out of bounds write in ANGLE. Reported by Google on 2026-05-10

[N/A][511784747] Medium CVE-2026-13924: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-05-10

[N/A][511802911] Medium CVE-2026-13925: Inappropriate implementation in Downloads. Reported by Google on 2026-05-10

[N/A][511814550] Medium CVE-2026-13926: Insufficient validation of untrusted input in Network. Reported by Google on 2026-05-10

[N/A][511826446] Medium CVE-2026-13927: Insufficient validation of untrusted input in UI. Reported by Google on 2026-05-10

[N/A][512162479] Medium CVE-2026-13928: Insufficient validation of untrusted input in Enterprise. Reported by Google on 2026-05-11

[TBD][512249559] Medium CVE-2026-13929: Insufficient validation of untrusted input in DevTools. Reported by LegioSec on 2026-05-12

[N/A][512937764] Medium CVE-2026-13930: Insufficient policy enforcement in Actor. Reported by Google on 2026-05-13

[N/A][512997441] Medium CVE-2026-13931: Inappropriate implementation in Media. Reported by Google on 2026-05-13

[N/A][513001690] Medium CVE-2026-13932: Inappropriate implementation in Sharing. Reported by Google on 2026-05-14

[N/A][513002625] Medium CVE-2026-13933: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-14

[N/A][513006636] Medium CVE-2026-13934: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-05-14

[N/A][513006745] Medium CVE-2026-14399: Uninitialized Use in Dawn. Reported by Google on 2026-05-14

[N/A][513009005] Medium CVE-2026-13935: Side-channel information leakage in ComputePressure. Reported by Google on 2026-05-14

[N/A][513044658] Medium CVE-2026-13936: Inappropriate implementation in Passwords. Reported by Google on 2026-05-14

[N/A][513046494] Medium CVE-2026-13937: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-14

[N/A][513143921] Medium CVE-2026-13938: Integer overflow in Fonts. Reported by Google on 2026-05-14

[N/A][513149760] Medium CVE-2026-13939: Insufficient validation of untrusted input in WebShare. Reported by Google on 2026-05-14

[N/A][513158425] Medium CVE-2026-13940: Uninitialized Use in Cast. Reported by Google on 2026-05-14

[N/A][513183855] Medium CVE-2026-13941: Inappropriate implementation in SiteSettings. Reported by Google on 2026-05-14

[N/A][513186670] Medium CVE-2026-13942: Insufficient validation of untrusted input in Video Capture. Reported by Google on 2026-05-14

[N/A][513204116] Medium CVE-2026-13943: Uninitialized Use in CSS. Reported by Google on 2026-05-14

[N/A][513224212] Medium CVE-2026-13944: Inappropriate implementation in DataTransfer. Reported by Google on 2026-05-14

[N/A][513226551] Medium CVE-2026-13945: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-14

[N/A][513274039] Medium CVE-2026-13946: Inappropriate implementation in ScriptInjections. Reported by Google on 2026-05-14

[N/A][513280648] Medium CVE-2026-13947: Uninitialized Use in XR. Reported by Google on 2026-05-14

[N/A][513286820] Medium CVE-2026-13948: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-14

[N/A][513311569] Medium CVE-2026-13949: Insufficient policy enforcement in Payments. Reported by Google on 2026-05-14

[N/A][513337989] Medium CVE-2026-14404: Inappropriate implementation in PDFium. Reported by Google on 2026-05-14

[N/A][513360781] Medium CVE-2026-13950: Uninitialized Use in GPU. Reported by Google on 2026-05-15

[N/A][513394321] Medium CVE-2026-13951: Policy bypass in USB. Reported by Google on 2026-05-15

[N/A][513401808] Medium CVE-2026-13952: Inappropriate implementation in PerformanceAPIs. Reported by Google on 2026-05-15

[N/A][513435594] Medium CVE-2026-14406: Out of bounds read in V8. Reported by Google on 2026-05-15

[N/A][513459192] Medium CVE-2026-13953: Inappropriate implementation in SplitView. Reported by Google on 2026-05-15

[N/A][513504934] Medium CVE-2026-13954: Insufficient policy enforcement in XML. Reported by Google on 2026-05-15

[N/A][513508305] Medium CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs. Reported by Google on 2026-05-15

[N/A][513515168] Medium CVE-2026-13956: Incorrect security UI in PageInfo. Reported by Google on 2026-05-15

[N/A][513553557] Medium CVE-2026-13957: Incorrect security UI in Extensions. Reported by Google on 2026-05-15

[N/A][513567306] Medium CVE-2026-13958: Uninitialized Use in Codecs. Reported by Google on 2026-05-15

[N/A][513586956] Medium CVE-2026-14407: Inappropriate implementation in V8. Reported by Google on 2026-05-15

[N/A][513609249] Medium CVE-2026-13959: Insufficient validation of untrusted input in Blink. Reported by Google on 2026-05-15

[N/A][513714023] Medium CVE-2026-13960: Inappropriate implementation in Passwords. Reported by Google on 2026-05-16

[N/A][513719481] Medium CVE-2026-13961: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513721370] Medium CVE-2026-13962: Insufficient data validation in PDF. Reported by Google on 2026-05-16

[N/A][513727626] Medium CVE-2026-13963: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513735096] Medium CVE-2026-13964: Insufficient policy enforcement in WebView. Reported by Google on 2026-05-16

[N/A][513737952] Medium CVE-2026-13965: Use after free in Oilpan. Reported by Google on 2026-05-16

[N/A][513741393] Medium CVE-2026-13966: Inappropriate implementation in History. Reported by Google on 2026-05-16

[N/A][513751951] Medium CVE-2026-13967: Type Confusion in V8. Reported by Google on 2026-05-16

[N/A][513762145] Medium CVE-2026-13968: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513762962] Medium CVE-2026-13969: Uninitialized Use in UI. Reported by Google on 2026-05-16

[N/A][513779283] Medium CVE-2026-13970: Uninitialized Use in Media. Reported by Google on 2026-05-16

[N/A][513780208] Medium CVE-2026-13971: Uninitialized Use in Skia. Reported by Google on 2026-05-16

[N/A][513792140] Medium CVE-2026-13972: Inappropriate implementation in Paint. Reported by Google on 2026-05-16

[N/A][513832989] Medium CVE-2026-13973: Inappropriate implementation in UI. Reported by Google on 2026-05-16

[N/A][513850475] Medium CVE-2026-13974: Integer overflow in Safe Browsing. Reported by Google on 2026-05-16

[N/A][513857658] Medium CVE-2026-13975: Out of bounds read in ANGLE. Reported by Google on 2026-05-16

[N/A][513858286] Medium CVE-2026-13976: Heap buffer overflow in Storage. Reported by Google on 2026-05-16

[N/A][513859894] Medium CVE-2026-13977: Inappropriate implementation in HTMLParser. Reported by Google on 2026-05-16

[N/A][513866949] Medium CVE-2026-13978: Insufficient policy enforcement in PageInfo. Reported by Google on 2026-05-16

[N/A][513948227] Medium CVE-2026-14414: Insufficient validation of untrusted input in Skia. Reported by Google on 2026-05-17

[N/A][513988889] Medium CVE-2026-13979: Inappropriate implementation in Paint. Reported by Google on 2026-05-17

[N/A][513989973] Medium CVE-2026-13980: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-17

[N/A][513990408] Medium CVE-2026-13981: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-17

[N/A][514006829] Medium CVE-2026-13982: Incorrect security UI in Passwords. Reported by Google on 2026-05-17

[N/A][514009910] Medium CVE-2026-13983: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-17

[N/A][514010404] Medium CVE-2026-13984: Incorrect security UI in TabStrip. Reported by Google on 2026-05-17

[N/A][514013849] Medium CVE-2026-13985: Inappropriate implementation in MediaCapture. Reported by Google on 2026-05-17

[N/A][514020959] Medium CVE-2026-13986: Inappropriate implementation in Media UI. Reported by Google on 2026-05-17

[N/A][514039122] Medium CVE-2026-13987: Incorrect security UI in Mobile. Reported by Google on 2026-05-17

[N/A][514040614] Medium CVE-2026-13988: Inappropriate implementation in Paint. Reported by Google on 2026-05-17

[N/A][514056221] Medium CVE-2026-13989: Insufficient policy enforcement in PageInfo. Reported by Google on 2026-05-17

[N/A][514058439] Medium CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer. Reported by Google on 2026-05-17

[N/A][514061117] Medium CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-17

[N/A][514063409] Medium CVE-2026-13992: Inappropriate implementation in UI. Reported by Google on 2026-05-17

[N/A][514064139] Medium CVE-2026-13993: Incorrect security UI in WebAppInstalls. Reported by Google on 2026-05-17

[N/A][514067416] Medium CVE-2026-13994: Inappropriate implementation in Credential Management. Reported by Google on 2026-05-17

[N/A][514067524] Medium CVE-2026-13995: Insufficient validation of untrusted input in Autofill. Reported by Google on 2026-05-17

[N/A][514068972] Medium CVE-2026-13996: Incorrect security UI in Permissions. Reported by Google on 2026-05-17

[N/A][514069689] Medium CVE-2026-13997: Incorrect security UI in Extensions. Reported by Google on 2026-05-17

[N/A][514070501] Medium CVE-2026-13998: Incorrect security UI in File Input. Reported by Google on 2026-05-17

[N/A][514071697] Medium CVE-2026-13999: Inappropriate implementation in Extensions. Reported by Google on 2026-05-17

[N/A][514461552] Medium CVE-2026-14000: Inappropriate implementation in XML. Reported by Google on 2026-05-19

[N/A][514481943] Medium CVE-2026-14001: Inappropriate implementation in Network. Reported by Google on 2026-05-19

[N/A][514489361] Medium CVE-2026-14002: Inappropriate implementation in Geolocation. Reported by Google on 2026-05-19

[N/A][514503077] Medium CVE-2026-14003: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-19

[N/A][514538751] Medium CVE-2026-14004: Inappropriate implementation in CSS. Reported by Google on 2026-05-19

[N/A][514740273] Medium CVE-2026-14005: Use after free in Omnibox. Reported by Google on 2026-05-19

[N/A][515423596] Medium CVE-2026-14006: Use after free in Navigation. Reported by Google on 2026-05-21

[N/A][516425999] Medium CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy. Reported by Google on 2026-05-25

[N/A][516781007] Medium CVE-2026-14008: Uninitialized Use in WebXR. Reported by Google on 2026-05-26

[N/A][516819850] Medium CVE-2026-14009: Insufficient data validation in Passwords. Reported by Google on 2026-05-26

[N/A][516924151] Medium CVE-2026-14010: Uninitialized Use in Codecs. Reported by Google on 2026-05-27

[N/A][516944556] Medium CVE-2026-14011: Out of bounds read in SurfaceCapture. Reported by Google on 2026-05-27

[N/A][517033235] Medium CVE-2026-14421: Uninitialized Use in Dawn. Reported by Google on 2026-05-27

[N/A][517110749] Medium CVE-2026-14012: Side-channel information leakage in CSS. Reported by Google on 2026-05-27

[N/A][517114175] Medium CVE-2026-14013: Inappropriate implementation in SVG. Reported by Google on 2026-05-27

[N/A][517155893] Medium CVE-2026-14014: Inappropriate implementation in Paint. Reported by Google on 2026-05-27

[N/A][517207235] Medium CVE-2026-14015: Inappropriate implementation in WebRTC. Reported by Google on 2026-05-27

[N/A][517234388] Medium CVE-2026-14016: Insufficient policy enforcement in SVG. Reported by Google on 2026-05-27

[N/A][517241992] Medium CVE-2026-14017: Inappropriate implementation in Navigation. Reported by Google on 2026-05-27

[N/A][517350251] Medium CVE-2026-14018: Use after free in Updater. Reported by Google on 2026-05-28

[N/A][517455455] Medium CVE-2026-14019: Inappropriate implementation in Passwords. Reported by Google on 2026-05-28

[N/A][517598518] Medium CVE-2026-14020: Insufficient validation of untrusted input in WebXR. Reported by Google on 2026-05-28

[N/A][517731924] Medium CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI. Reported by Google on 2026-05-29

[N/A][517791835] Medium CVE-2026-14022: Insufficient validation of untrusted input in Network. Reported by Google on 2026-05-29

[N/A][518063436] Medium CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI. Reported by Google on 2026-05-30

[N/A][518245882] Medium CVE-2026-14024: Use after free in Ozone. Reported by Google on 2026-05-30

[N/A][524290062] Medium CVE-2026-14432: Use after free in V8. Reported by Google on 2026-06-15

[$2000][506482786] Low CVE-2026-14025: Use after free in Views. Reported by asjidkalam on 2026-04-26

[$1000][507263861] Low CVE-2026-14026: Incorrect security UI in SplitView. Reported by adisahilna35@gmail.com on 2026-04-28

[TBD][361375787] Low CVE-2026-14027: Use after free in SignIn. Reported by Sven Dysthe (@svn-dys) on 2024-08-21

[TBD][401816601] Low CVE-2026-14028: Incorrect security UI in Chrome for iOS. Reported by Ameen Basha M K on 2025-03-09

[TBD][488762971] Low CVE-2026-14030: Incorrect security UI in SplitView. Reported by Khalil Zhani on 2026-03-01

[N/A][495459838] Low CVE-2026-14031: Incorrect security UI in File Input. Reported by Google on 2026-03-23

[N/A][495783474] Low CVE-2026-14032: Use after free in Bluetooth. Reported by Google on 2026-03-24

[N/A][495848160] Low CVE-2026-14033: Insufficient policy enforcement in Media. Reported by Google on 2026-03-24

[N/A][496368832] Low CVE-2026-14034: Inappropriate implementation in WebXR. Reported by Google on 2026-03-26

[N/A][496371586] Low CVE-2026-14035: Insufficient policy enforcement in Bluetooth. Reported by Google on 2026-03-26

[N/A][496411061] Low CVE-2026-14036: Insufficient policy enforcement in Bluetooth. Reported by Google on 2026-03-26

[N/A][496522611] Low CVE-2026-14037: Insufficient policy enforcement in GPU. Reported by Google on 2026-03-26

[N/A][497241148] Low CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page. Reported by Google on 2026-03-28

[N/A][497358012] Low CVE-2026-14039: Insufficient policy enforcement in GetUserMedia. Reported by Google on 2026-03-29

[N/A][497488593] Low CVE-2026-14040: Use after free in BrowserTag. Reported by Google on 2026-03-29

[N/A][497544822] Low CVE-2026-14041: Insufficient policy enforcement in Serial. Reported by Google on 2026-03-29

[N/A][497558336] Low CVE-2026-14042: Inappropriate implementation in Isolated Web Apps. Reported by Google on 2026-03-29

[N/A][497632232] Low CVE-2026-14043: Use after free in GetUserMedia. Reported by Google on 2026-03-30

[N/A][497670996] Low CVE-2026-14044: Use after free in ANGLE. Reported by Google on 2026-03-30

[N/A][497723649] Low CVE-2026-14045: Insufficient validation of untrusted input in Network. Reported by Google on 2026-03-30

[N/A][497959724] Low CVE-2026-14046: Inappropriate implementation in CustomTabs. Reported by Google on 2026-03-30

[N/A][498864176] Low CVE-2026-14047: Insufficient policy enforcement in Extensions. Reported by Google on 2026-04-02

[N/A][499189601] Low CVE-2026-14048: Use after free in Chromecast. Reported by Google on 2026-04-03

[N/A][501659888] Low CVE-2026-14049: Inappropriate implementation in GPU. Reported by Google on 2026-04-11

[N/A][501708647] Low CVE-2026-14050: Insufficient policy enforcement in Passwords. Reported by Google on 2026-04-11

[N/A][501747804] Low CVE-2026-14051: Uninitialized Use in GamepadAPI. Reported by Google on 2026-04-11

[N/A][501810874] Low CVE-2026-14052: Insufficient policy enforcement in FileSystem. Reported by Google on 2026-04-12

[N/A][501836539] Low CVE-2026-14053: Insufficient policy enforcement in Extensions. Reported by Google on 2026-04-12

[N/A][501851312] Low CVE-2026-14054: Insufficient policy enforcement in Network. Reported by Google on 2026-04-12

[N/A][501857663] Low CVE-2026-14055: Insufficient validation of untrusted input in Device Trust. Reported by Google on 2026-04-12

[N/A][501888426] Low CVE-2026-14056: Insufficient validation of untrusted input in Media. Reported by Google on 2026-04-12

[N/A][502212647] Low CVE-2026-14057: Insufficient policy enforcement in FedCM. Reported by Google on 2026-04-13

[N/A][502354038] Low CVE-2026-14058: Policy bypass in Parser. Reported by Google on 2026-04-14

[N/A][502363986] Low CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets. Reported by Google on 2026-04-14

[N/A][502372527] Low CVE-2026-14060: Insufficient validation of untrusted input in Chromoting. Reported by Google on 2026-04-14

[N/A][502434484] Low CVE-2026-14061: Inappropriate implementation in Dawn. Reported by Google on 2026-04-14

[N/A][502448128] Low CVE-2026-14062: Inappropriate implementation in Views. Reported by Google on 2026-04-14

[N/A][502473563] Low CVE-2026-14063: Out of bounds memory access in Chromecast. Reported by Google on 2026-04-14

[N/A][502714977] Low CVE-2026-14064: Use after free in PageInfo. Reported by Google on 2026-04-15

[N/A][503617508] Low CVE-2026-14065: Insufficient validation of untrusted input in PageInfo. Reported by Google on 2026-04-17

[N/A][503779807] Low CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-04-17

[N/A][504069465] Low CVE-2026-14067: Use after free in Chrome for iOS. Reported by Google on 2026-04-18

[N/A][504210171] Low CVE-2026-14068: Inappropriate implementation in Omnibox. Reported by Google on 2026-04-19

[N/A][505136542] Low CVE-2026-14069: Integer overflow in WebNN. Reported by Google on 2026-04-21

[N/A][505137978] Low CVE-2026-14070: Uninitialized Use in WebNN. Reported by Google on 2026-04-21

[N/A][506143724] Low CVE-2026-14071: Side-channel information leakage in WebAudio. Reported by Google on 2026-04-24

[N/A][507099867] Low CVE-2026-14072: Incorrect security UI in SplitView. Reported by FARISSAL B on 2026-04-28

[N/A][507237563] Low CVE-2026-14073: Insufficient policy enforcement in WebXR. Reported by Google on 2026-04-28

[N/A][511263221] Low CVE-2026-14394: Use after free in V8. Reported by Google on 2026-05-08

[N/A][511290389] Low CVE-2026-14395: Out of bounds write in V8. Reported by Google on 2026-05-08

[N/A][511743480] Low CVE-2026-14074: Side-channel information leakage in WebAuthentication. Reported by Google on 2026-05-10

[N/A][511808800] Low CVE-2026-14075: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-10

[N/A][511815165] Low CVE-2026-14076: Policy bypass in Network. Reported by Google on 2026-05-10

[TBD][511869411] Low CVE-2026-14077: Incorrect security UI in Select. Reported by pwn.ai on 2026-05-11

[N/A][512953564] Low CVE-2026-14078: Policy bypass in WebRTC. Reported by Google on 2026-05-13

[N/A][512971938] Low CVE-2026-14079: Policy bypass in Network. Reported by Google on 2026-05-13

[N/A][512997517] Low CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher. Reported by Google on 2026-05-13

[N/A][513030698] Low CVE-2026-14081: Insufficient policy enforcement in DevTools. Reported by Google on 2026-05-14

[N/A][513049578] Low CVE-2026-14082: Race in Storage. Reported by Google on 2026-05-14

[N/A][513128322] Low CVE-2026-14083: Insufficient validation of untrusted input in HTML. Reported by Google on 2026-05-14

[N/A][513138148] Low CVE-2026-14084: Insufficient validation of untrusted input in Chromoting. Reported by Google on 2026-05-14

[N/A][513155863] Low CVE-2026-14085: Side-channel information leakage in CSS. Reported by Google on 2026-05-14

[N/A][513169718] Low CVE-2026-14086: Insufficient policy enforcement in HID. Reported by Google on 2026-05-14

[N/A][513177237] Low CVE-2026-14087: Insufficient validation of untrusted input in WebNN. Reported by Google on 2026-05-14

[N/A][513178869] Low CVE-2026-14088: Uninitialized Use in Canvas. Reported by Google on 2026-05-14

[N/A][513188254] Low CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker. Reported by Google on 2026-05-14

[N/A][513194241] Low CVE-2026-14090: Out of bounds read in CameraCapture. Reported by Google on 2026-05-14

[N/A][513208773] Low CVE-2026-14091: Use after free in DevTools. Reported by Google on 2026-05-14

[N/A][513212892] Low CVE-2026-14092: Insufficient policy enforcement in Privacy. Reported by Google on 2026-05-14

[N/A][513240099] Low CVE-2026-14093: Use after free in Cast. Reported by Google on 2026-05-14

[N/A][513264273] Low CVE-2026-14094: Use after free in Installer. Reported by Google on 2026-05-14

[N/A][513271007] Low CVE-2026-14095: Insufficient validation of untrusted input in Browser. Reported by Google on 2026-05-14

[N/A][513298483] Low CVE-2026-14403: Use after free in V8. Reported by Google on 2026-05-14

[N/A][513310821] Low CVE-2026-14096: Object lifecycle issue in Input. Reported by Google on 2026-05-14

[N/A][513333529] Low CVE-2026-14097: Inappropriate implementation in WebAppInstalls. Reported by Google on 2026-05-14

[N/A][513375767] Low CVE-2026-14098: Inappropriate implementation in CSS. Reported by Google on 2026-05-15

[N/A][513376037] Low CVE-2026-14405: Uninitialized Use in V8. Reported by Google on 2026-05-15

[N/A][513382161] Low CVE-2026-14099: Use after free in Chrome for iOS. Reported by Google on 2026-05-15

[N/A][513383891] Low CVE-2026-14100: Insufficient data validation in NetworkCache. Reported by Google on 2026-05-15

[N/A][513454805] Low CVE-2026-14101: Insufficient policy enforcement in Sandbox. Reported by Google on 2026-05-15

[N/A][513455047] Low CVE-2026-14102: Use after free in Passwords. Reported by Google on 2026-05-15

[N/A][513465245] Low CVE-2026-14103: Use after free in SSL. Reported by Google on 2026-05-15

[N/A][513484193] Low CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google on 2026-05-15

[N/A][513528117] Low CVE-2026-14105: Insufficient policy enforcement in Speech. Reported by Google on 2026-05-15

[N/A][513532778] Low CVE-2026-14106: Insufficient validation of untrusted input in Text. Reported by Google on 2026-05-15

[N/A][513544566] Low CVE-2026-14107: Use after free in Scheduling. Reported by Google on 2026-05-15

[N/A][513689974] Low CVE-2026-14108: Use after free in PDFium. Reported by Google on 2026-05-15

[N/A][513694957] Low CVE-2026-14109: Insufficient policy enforcement in Mojo. Reported by Google on 2026-05-16

[N/A][513698452] Low CVE-2026-14110: Inappropriate implementation in DarkMode. Reported by Google on 2026-05-16

[N/A][513710926] Low CVE-2026-14111: Use after free in WebProtect. Reported by Google on 2026-05-16

[N/A][513713946] Low CVE-2026-14112: Inappropriate implementation in Enterprise. Reported by Google on 2026-05-16

[N/A][513737335] Low CVE-2026-14113: Use after free in Updater. Reported by Google on 2026-05-16

[N/A][513743129] Low CVE-2026-14114: Inappropriate implementation in WebAppInstalls. Reported by Google on 2026-05-16

[N/A][513745699] Low CVE-2026-14115: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-16

[N/A][513747800] Low CVE-2026-14116: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513751020] Low CVE-2026-14117: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16

[N/A][513772764] Low CVE-2026-14118: Insufficient data validation in DevTools. Reported by Google on 2026-05-16

[N/A][513775483] Low CVE-2026-14119: Type Confusion in Bluetooth. Reported by Google on 2026-05-16

[N/A][513777411] Low CVE-2026-14120: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16

[N/A][513789382] Low CVE-2026-14121: Use after free in Chromoting. Reported by Google on 2026-05-16

[TBD][513810921] Low CVE-2026-14409: Inappropriate implementation in V8. Reported by Yuntao You (@GraVity0) of Bytedance Wuheng Lab on 2026-05-16

[N/A][513824891] Low CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google on 2026-05-16

[N/A][513836996] Low CVE-2026-14410: Inappropriate implementation in Skia. Reported by Google on 2026-05-16

[N/A][513856644] Low CVE-2026-14123: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-16

[N/A][513867710] Low CVE-2026-14124: Inappropriate implementation in CredentialProvider. Reported by Google on 2026-05-16

[N/A][513918431] Low CVE-2026-14125: Uninitialized Use in ANGLE. Reported by Google on 2026-05-17

[N/A][513992796] Low CVE-2026-14126: Incorrect security UI in UI. Reported by Google on 2026-05-17

[N/A][514009654] Low CVE-2026-14127: Inappropriate implementation in Printing. Reported by Google on 2026-05-17

[N/A][514015836] Low CVE-2026-14128: Insufficient data validation in Chrome for iOS. Reported by Google on 2026-05-17

[N/A][514018024] Low CVE-2026-14129: Incorrect security UI in PreviewTab. Reported by Google on 2026-05-17

[N/A][514019522] Low CVE-2026-14130: Incorrect security UI in Omnibox. Reported by Google on 2026-05-17

[N/A][514020982] Low CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google on 2026-05-17

[N/A][514039492] Low CVE-2026-14132: Inappropriate implementation in WebXR. Reported by Google on 2026-05-17

[N/A][514039947] Low CVE-2026-14133: Race in History Embeddings. Reported by Google on 2026-05-17

[N/A][514055973] Low CVE-2026-14134: Inappropriate implementation in Autofill. Reported by Google on 2026-05-17

[N/A][514058566] Low CVE-2026-14135: Insufficient validation of untrusted input in Network. Reported by Google on 2026-05-17

[N/A][514068611] Low CVE-2026-14136: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-17

[N/A][514070067] Low CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-17

[N/A][514071775] Low CVE-2026-14138: Inappropriate implementation in WebAppInstalls. Reported by Google on 2026-05-17

[N/A][514072495] Low CVE-2026-14139: Inappropriate implementation in TabStrip. Reported by Google on 2026-05-17

[N/A][514072607] Low CVE-2026-14140: Insufficient validation of untrusted input in Input. Reported by Google on 2026-05-17

[N/A][514072867] Low CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture. Reported by Google on 2026-05-17

[N/A][514073460] Low CVE-2026-14142: Inappropriate implementation in Extensions. Reported by Google on 2026-05-17

[N/A][514075028] Low CVE-2026-14143: Incorrect security UI in Passwords. Reported by Google on 2026-05-17

[N/A][514079793] Low CVE-2026-14144: Incorrect security UI in Views. Reported by Google on 2026-05-17

[N/A][514485825] Low CVE-2026-14145: Inappropriate implementation in CSS. Reported by Google on 2026-05-19

[N/A][514550047] Low CVE-2026-14146: Inappropriate implementation in CSS. Reported by Google on 2026-05-19

[N/A][514632767] Low CVE-2026-14147: Inappropriate implementation in CSS. Reported by Google on 2026-05-19

[N/A][515086856] Low CVE-2026-14415: Inappropriate implementation in V8. Reported by Google on 2026-05-20

[N/A][515426873] Low CVE-2026-14148: Type Confusion in CSS. Reported by Google on 2026-05-21

[N/A][515427046] Low CVE-2026-14149: Use after free in Audio. Reported by Google on 2026-05-21

[N/A][515428315] Low CVE-2026-14416: Out of bounds read in Dawn. Reported by Google on 2026-05-21

[N/A][517376041] Low CVE-2026-14150: Insufficient validation of untrusted input in Speech. Reported by Google on 2026-05-28

[N/A][517381770] Low CVE-2026-14151: Inappropriate implementation in AI. Reported by Google on 2026-05-28

[N/A][517534944] Low CVE-2026-14152: Out of bounds write in ANGLE. Reported by Google on 2026-05-28

[N/A][517684077] Low CVE-2026-14153: Inappropriate implementation in Glic. Reported by Google on 2026-05-29

[N/A][517741170] Low CVE-2026-14154: Inappropriate implementation in DevTools. Reported by Google on 2026-05-29

[N/A][518246925] Low CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI. Reported by Google on 2026-05-30

[N/A][518247789] Low CVE-2026-14156: Policy bypass in StorageAccessAPI. Reported by Google on 2026-05-30


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

26 Juni 2026 om 00:00

The Stable channel has been updated to 149.0.7827.200/201 for Windows and Mac and 149.0.7827.200 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 3 security fixes. Please see the Chrome Security Pagefor more information.


[N/A][513138301] High CVE-2026-13281: Integer overflow in Mojo. Reported by Google on 2026-05-14

[N/A][517522620] High CVE-2026-13282: Use after free in Payments. Reported by Google on 2026-05-28

[N/A][522561151] High CVE-2026-13283: Use after free in AdFilter. Reported by Google on 2026-06-11


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.



Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Early Stable Update for Desktop

24 Juni 2026 om 21:05

The Stable channel has been updated to 150.0.7871.46/.47 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Extended Stable Update for Desktop

23 Juni 2026 om 20:59

The Extended Stable channel has been updated to 148.0.7778.280 for Windows and Mac which will roll out over the coming days/weeks.


A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Daniel Yip
Google Chrome
  •  

Stable Channel Update for Desktop

24 Juni 2026 om 20:37

The Stable channel has been updated to 149.0.7827.196/197 for Windows and Mac and 149.0.7827.196 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log


Security Fixes and Rewards


Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 18 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information


[TBD][520656244] Critical CVE-2026-13028: Use after free in WebGL. Reported by anonymous on 2026-06-07

[N/A][523591974] Critical CVE-2026-13032: Use after free in WebGL. Reported by Google on 2026-06-13

[N/A][523677844] Critical CVE-2026-13033: Out of bounds read in Blink>InterestGroups. Reported by Google on 2026-06-13

[N/A][523740781] Critical CVE-2026-13038: Use after free in Autofill. Reported by Google on 2026-06-14

[N/A][511776603] High CVE-2026-13021: Inappropriate implementation in DeviceBoundSessionCredentials. Reported by Google on 2026-05-10

[N/A][516734537] High CVE-2026-13022: Inappropriate implementation in Autofill. Reported by Google on 2026-05-26

[N/A][517080836] High CVE-2026-13023: Uninitialized Use in GPU. Reported by Google on 2026-05-27

[N/A][517148260] High CVE-2026-13024: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-05-27

[N/A][518043569] High CVE-2026-13025: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-30

[N/A][519728279] High CVE-2026-13026: Use after free in Digital Credentials. Reported by Google on 2026-06-03

[N/A][520543781] High CVE-2026-13027: Use after free in FileSystem. Reported by Google on 2026-06-05

[N/A][521495992] High CVE-2026-13029: Use after free in Web Authentication. Reported by Google on 2026-06-08

[N/A][522840723] High CVE-2026-13030: Uninitialized Use in GPU. Reported by Google on 2026-06-11

[N/A][523308824] High CVE-2026-13031: Use after free in Blink. Reported by Google on 2026-06-12

[N/A][523699355] High CVE-2026-13034: Inappropriate implementation in Passwords. Reported by Google on 2026-06-13

[N/A][523704570] High CVE-2026-13035: Use after free in Bluetooth. Reported by Google on 2026-06-13

[N/A][523711130] High CVE-2026-13036: Use after free in Blink. Reported by Google on 2026-06-13

[N/A][523721871] High CVE-2026-13037: Use after free in WebView. Reported by Google on 2026-06-14


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Early Stable Update for Desktop

17 Juni 2026 om 18:10

The Stable channel has been updated to 150.0.7871.24/.25 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Stable Channel Update for Desktop

17 Juni 2026 om 03:32

The Stable channel has been updated to 149.0.7827.155/.156 for Windows and Mac and 149.0.7827.155 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 33 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.


[N/A][516496659] Critical CVE-2026-12437: Use after free in WebShare. Reported by Google on 2026-05-25

[N/A][516947912] Critical CVE-2026-12438: Inappropriate implementation in WebView. Reported by Google on 2026-05-27

[N/A][519728275] Critical CVE-2026-12439: Use after free in Digital Credentials. Reported by Google on 2026-06-03

[N/A][519731619] Critical CVE-2026-12440: Use after free in DigitalCredentials. Reported by Google on 2026-06-03

[N/A][520157118] Critical CVE-2026-12441: Use after free in File Input. Reported by Google on 2026-06-05

[N/A][521950423] Critical CVE-2026-12442: Use after free in Passwords. Reported by Google on 2026-06-09

[N/A][522566295] Critical CVE-2026-12443: Use after free in Web Authentication. Reported by Google on 2026-06-11

[N/A][513160088] High CVE-2026-12444: Out of bounds read in Chromoting. Reported by Google on 2026-05-14

[N/A][513199795] High CVE-2026-12445: Use after free in Extensions. Reported by Google on 2026-05-14

[N/A][513313107] High CVE-2026-12446: Insufficient data validation in Passwords. Reported by Google on 2026-05-14

[N/A][513405023] High CVE-2026-12447: Heap buffer overflow in WebRTC. Reported by Google on 2026-05-15

[N/A][513458233] High CVE-2026-12448: Inappropriate implementation in WebView. Reported by Google on 2026-05-15

[N/A][513480539] High CVE-2026-12449: Use after free in Chromoting. Reported by Google on 2026-05-15

[N/A][514531776] High CVE-2026-12450: Inappropriate implementation in Media. Reported by Zhixin Tu on 2026-05-19

[N/A][514741076] High CVE-2026-12451: Use after free in DigitalCredentials. Reported by Google on 2026-05-19

[N/A][515462244] High CVE-2026-12452: Use after free in Downloads. Reported by Google on 2026-05-21

[N/A][516448843] High CVE-2026-12453: Insufficient validation of untrusted input in Input. Reported by Google on 2026-05-25

[N/A][516926968] High CVE-2026-12454: Race in Safe Browsing. Reported by Google on 2026-05-27

[N/A][517069848] High CVE-2026-12455: Use after free in Tab Strip. Reported by Google on 2026-05-27

[N/A][517124587] High CVE-2026-12456: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-27

[N/A][517153117] High CVE-2026-12457: Insufficient data validation in Extensions. Reported by Google on 2026-05-27

[N/A][517258337] High CVE-2026-12458: Incorrect security UI in Passwords. Reported by Google on 2026-05-27

[N/A][517406035] High CVE-2026-12459: Inappropriate implementation in Serial. Reported by Google on 2026-05-28

[N/A][517484284] High CVE-2026-12460: Insufficient policy enforcement in File System Access. Reported by Google on 2026-05-28

[N/A][517727318] High CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google on 2026-05-29

[N/A][517916024] High CVE-2026-12462: Use after free in Media. Reported by Google on 2026-05-29

[N/A][518042749] High CVE-2026-12463: Inappropriate implementation in Views. Reported by Google on 2026-05-30

[N/A][519358344] High CVE-2026-12464: Use after free in Browser. Reported by Google on 2026-06-03

[N/A][520189702] High CVE-2026-12465: Insufficient validation of untrusted input in Metrics. Reported by Google on 2026-06-05

[N/A][520199394] High CVE-2026-12466: Heap buffer overflow in WebRTC. Reported by Google on 2026-06-05

[N/A][520202726] High CVE-2026-12467: Use after free in Extensions. Reported by Google on 2026-06-05

[N/A][521485244] High CVE-2026-12468: Inappropriate implementation in Updater. Reported by Google on 2026-06-08

[N/A][521618871] High CVE-2026-12469: Uninitialized Use in GPU. Reported by Google on 2026-06-09


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

Extended Stable Update for Desktop

16 Juni 2026 om 23:30

The Extended Stable channel has been updated to 148.0.7778.271 for Windows and Mac which will roll out over the coming days/weeks.


A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Daniel Yip
Google Chrome
  •  
❌