Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 108 security fixes. Please see the Chrome Security Page for more information.
[$5,000][551573368] Critical CVE-2026-95350: Buffer overflow in ANGLE. Reported by Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng of STAR Labs SG Pte. LTd. on 2026-08-24
[$2,500][530045332] Critical CVE-2026-95357: Out of bounds write in GPU. Reported by Anymous on 2026-07-01
[TBD][548585299] Critical CVE-2026-95339: Use after free in ServiceWorker. Reported by Andrew Boni on 2026-08-18
[TBD][551708184] Critical CVE-2026-95281: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan of STAR Labs SG Pte. Ltd. on 2026-08-24
[TBD][552665794] Critical CVE-2026-95313: Use after free in Fullscreen. Reported by WinD39 - Huynh Dinh Vu on 2026-08-26
[N/A][553172761] Critical CVE-2026-95349: Buffer overflow in WebGL. Reported by Google on 2026-08-27
[TBD][556435507] Critical CVE-2026-95284: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan (STARLABS SG) on 2026-09-03
[TBD][556576992] Critical CVE-2026-95322: Out of bounds write in GPU. Reported by David Sievers (@loknop) on 2026-09-03
[N/A][559320837] Critical CVE-2026-95329: Out of bounds write in WebGL. Reported by Google on 2026-09-09
[TBD][560439699] Critical CVE-2026-95356: Use after free in WindowDialog. Reported by Xinyang Ge on 2026-09-12
[TBD][562151598] Critical CVE-2026-95310: Use after free in AdFilter. Reported by Xinyang Ge on 2026-09-16
[$5,000][540265100] High CVE-2026-95301: Missing authorization in Extensions. Reported by OGINOME Tomohito on 2026-07-29
[$5,000][543471693] High CVE-2026-95291: UI misrepresentation in SecurityIndicators. Reported by NH DEV on 2026-08-07
[N/A][508462481] High CVE-2026-95355: Incorrect authorization in Navigation. Reported by Google on 2026-05-01
[N/A][517661385] High CVE-2026-95315: Use after free in Aura. Reported by Google on 2026-05-29
[N/A][520516206] High CVE-2026-95298: Use after free in Browser. Reported by Google on 2026-06-05
[N/A][534997484] High CVE-2026-95372: Use after free in Chromecast. Reported by Google on 2026-07-15
[N/A][537857253] High CVE-2026-95324: Uninitialized resource in GPU. Reported by Google on 2026-07-22
[N/A][543141419] High CVE-2026-95283: Buffer overflow in Tint. Reported by Google on 2026-08-06
[TBD][550953039] High CVE-2026-95293: Uninitialized resource in GPU. Reported by TienPA - NGS Holdings on 2026-08-22
[N/A][553116160] High CVE-2026-95274: Improper output encoding in DevTools. Reported by Google on 2026-08-26
[N/A][553129513] High CVE-2026-95282: Use after free in Platform. Reported by Google on 2026-08-26
[N/A][553130481] High CVE-2026-95373: Use after free in DevTools. Reported by Google on 2026-08-26
[N/A][553136141] High CVE-2026-95277: Use after free in Views. Reported by Google on 2026-08-26
[N/A][554558320] High CVE-2026-95348: Use after free in Bluetooth. Reported by Google on 2026-08-29
[TBD][555299641] High CVE-2026-95335: Use after free in HID. Reported by WinD39 - Huynh Dinh Vu on 2026-09-01
[TBD][556535630] High CVE-2026-95338: Use after free in PDFium. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) on 2026-09-03
[TBD][556576976] High CVE-2026-95318: Buffer overflow in Video. Reported by alex.laboirie on 2026-09-03
[TBD][557523002] High CVE-2026-95286: Type confusion in Bindings. Reported by @bean5oup on 2026-09-05
[TBD][558764482] High CVE-2026-95365: Type confusion in IndexedDB. Reported by HoneyBee on 2026-09-08
[TBD][559815527] High CVE-2026-95343: Use after free in WebAudio. Reported by HoneyBee on 2026-09-11
[N/A][560406548] High CVE-2026-95280: Race condition in V8. Reported by Google on 2026-09-12
[TBD][560536731] High CVE-2026-95304: Out of bounds write in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12
[TBD][560536735] High CVE-2026-95306: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12
[N/A][561997427] High CVE-2026-95299: Use after free in GPU. Reported by Google on 2026-09-15
[TBD][562242429] High CVE-2026-95351: Use after free in Views. Reported by Xinyang Ge on 2026-09-16
[N/A][495529018] Medium CVE-2026-95287: Missing authorization in Navigation. Reported by Google on 2026-03-23
[N/A][497204165] Medium CVE-2026-95366: Use of released resource in Core. Reported by Google on 2026-03-28
[N/A][497212105] Medium CVE-2026-95382: Improper input validation in Auth. Reported by Google on 2026-03-28
[N/A][497603247] Medium CVE-2026-95381: Improper input validation in Printing. Reported by Google on 2026-03-30
[N/A][500127519] Medium CVE-2026-95331: Out of bounds write in ANGLE. Reported by Google on 2026-04-06
[N/A][501648493] Medium CVE-2026-95297: Missing authorization in Contextual Tasks. Reported by Google on 2026-04-11
[N/A][502179319] Medium CVE-2026-95375: Incorrect authorization in BrowserTag. Reported by Google on 2026-04-13
[N/A][502242455] Medium CVE-2026-95302: Incorrect authorization in WebAPKs. Reported by Google on 2026-04-13
[N/A][511791538] Medium CVE-2026-95362: Cross-site request forgery in DevTools. Reported by Google on 2026-05-10
[N/A][513049042] Medium CVE-2026-95369: Inappropriate implementation in XML. Reported by Google on 2026-05-14
[N/A][513134076] Medium CVE-2026-95376: Externally controlled reference in DevTools. Reported by Google on 2026-05-14
[N/A][513162143] Medium CVE-2026-95359: Uninitialized resource in GPU. Reported by Google on 2026-05-14
[N/A][513992281] Medium CVE-2026-95294: UI misrepresentation in Browser. Reported by Google on 2026-05-17
[N/A][514019137] Medium CVE-2026-95337: UI misrepresentation in Messages. Reported by Google on 2026-05-17
[N/A][514059630] Medium CVE-2026-95346: UI misrepresentation in Chromoting. Reported by Google on 2026-05-17
[N/A][514072284] Medium CVE-2026-95320: Missing authorization in Navigation. Reported by Google on 2026-05-17
[N/A][514487499] Medium CVE-2026-95317: Incorrect authorization in MediaCapture. Reported by Google on 2026-05-19
[N/A][516404074] Medium CVE-2026-95345: Use after free in Actor. Reported by Google on 2026-05-25
[N/A][517163294] Medium CVE-2026-95330: Improper state validation in Downloads. Reported by Google on 2026-05-27
[N/A][517417437] Medium CVE-2026-95370: Inappropriate implementation in NFC. Reported by Google on 2026-05-28
[N/A][517442714] Medium CVE-2026-95303: Incomplete cleanup in SmartCard. Reported by Google on 2026-05-28
[N/A][517584808] Medium CVE-2026-95360: Race condition in Editing. Reported by Google on 2026-05-28
[N/A][517596255] Medium CVE-2026-95295: Information leak in Mobile. Reported by Google on 2026-05-28
[N/A][517730821] Medium CVE-2026-95276: Improper input validation in Themes. Reported by Google on 2026-05-29
[N/A][517802696] Medium CVE-2026-95314: Incorrect authorization in HID. Reported by Google on 2026-05-29
[N/A][520504291] Medium CVE-2026-95371: Missing authorization in Views. Reported by Google on 2026-06-05
[N/A][522061704] Medium CVE-2026-95353: Use after free in Bindings. Reported by Google on 2026-06-10
[N/A][522344883] Medium CVE-2026-95363: UI misrepresentation in FileSystem. Reported by Google on 2026-06-10
[N/A][523719002] Medium CVE-2026-95341: Improper input validation in Desktop. Reported by Google on 2026-06-14
[N/A][524582798] Medium CVE-2026-95354: Use after free in Verifier. Reported by Google on 2026-06-16
[N/A][526550688] Medium CVE-2026-95384: Race condition in Transactions Platform. Reported by Google on 2026-06-22
[N/A][532962621] Medium CVE-2026-95336: Information leak in Transactions Platform. Reported by Google on 2026-07-09
[N/A][536161355] Medium CVE-2026-95290: Missing authorization in NFC. Reported by Google on 2026-07-18
[N/A][536648933] Medium CVE-2026-95325: Use after free in ANGLE. Reported by Google on 2026-07-19
[TBD][542926849] Medium CVE-2026-95275: Incorrect reference resolution in MediaStream. Reported by Zabith Mohammed (@nmzabith) on 2026-08-05
[TBD][543464436] Medium CVE-2026-95374: Incorrect authorization in Network. Reported by NH DEV on 2026-08-07
[N/A][545449081] Medium CVE-2026-95300: Missing authorization in DevTools. Reported by Google on 2026-08-12
[TBD][545879261] Medium CVE-2026-95321: UI misrepresentation in Payments. Reported by jodyritonga on 2026-08-13
[TBD][546438368] Medium CVE-2026-95323: UI misrepresentation in Chromium. Reported by Wihdatu Nuuro Ahmadi on 2026-08-14
[N/A][546639650] Medium CVE-2026-95332: Use of uninitialized variable in Tint. Reported by Google on 2026-08-14
[N/A][547832510] Medium CVE-2026-95312: Information leak in Passwords. Reported by Google on 2026-08-17
[TBD][548611433] Medium CVE-2026-95344: Race condition in DevTools. Reported by @bean5oup on 2026-08-18
[TBD][549911100] Medium CVE-2026-95289: Incorrect authorization in Scroll. Reported by Vu Van Tien (@n0_Be3r) on 2026-08-21
[TBD][550181232] Medium CVE-2026-95347: Use after free in Updater. Reported by a45hif on 2026-08-21
[N/A][553123003] Medium CVE-2026-95311: Free of non-heap memory in Fonts. Reported by Google on 2026-08-26
[N/A][553141660] Medium CVE-2026-95358: Incorrect authorization in Mobile. Reported by Google on 2026-08-26
[TBD][559682346] Medium CVE-2026-95333: Use after free in Metrics. Reported by sean geofrey on 2026-09-10
[$500][423956129] Low CVE-2026-95307: UI misrepresentation in ExtensionsMenu. Reported by Hafiizh on 2025-06-11
[N/A][497094708] Low CVE-2026-95285: Missing authorization in WebView. Reported by Google on 2026-03-28
[N/A][497344014] Low CVE-2026-95278: Missing authorization in WakeLock. Reported by Google on 2026-03-29
[N/A][502077689] Low CVE-2026-95327: Information leak in Networking. Reported by Google on 2026-04-13
[N/A][513403696] Low CVE-2026-95334: Incorrect reference resolution in WebProtect. Reported by Google on 2026-05-15
[N/A][513714849] Low CVE-2026-95308: Integer overflow in Metrics. Reported by Google on 2026-05-16
[N/A][513781838] Low CVE-2026-95292: Incorrect authorization in Safebrowsing. Reported by Google on 2026-05-16
[N/A][513791872] Low CVE-2026-95352: Incorrect authorization in DevTools. Reported by Google on 2026-05-16
[N/A][514012689] Low CVE-2026-95279: UI misrepresentation in Omnibox. Reported by Google on 2026-05-17
[N/A][514524620] Low CVE-2026-95367: Information leak in DataTransfer. Reported by Google on 2026-05-19
[N/A][517192965] Low CVE-2026-95385: Inappropriate implementation in PlatformIntegration. Reported by Google on 2026-05-27
[N/A][522413520] Low CVE-2026-95368: Incorrect authorization in DevTools. Reported by Google on 2026-06-10
[N/A][523765972] Low CVE-2026-95319: Use after free in Printing. Reported by Google on 2026-06-14
[N/A][533041383] Low CVE-2026-95326: Incomplete cleanup in Bluetooth. Reported by Google on 2026-07-09
[N/A][533074595] Low CVE-2026-95309: UI misrepresentation in Mobile. Reported by Google on 2026-07-09
[N/A][533095855] Low CVE-2026-95361: Confused deputy in DevTools. Reported by Google on 2026-07-09
[N/A][533102653] Low CVE-2026-95288: UI misrepresentation in Mobile. Reported by Google on 2026-07-09
[N/A][534579660] Low CVE-2026-95380: Type confusion in V8. Reported by Google on 2026-07-14
[TBD][547027738] Low CVE-2026-95342: Missing authorization in V8. Reported by Hongwei Li, Zhun Wang, Ziyue Pan, Junmin Zhu, Saastha Vasan, and Wenbo Guo on 2026-08-16
[TBD][551296612] Low CVE-2026-95296: Missing authorization in Core. Reported by Quyền Sơn (@zer0qs1337) on 2026-08-23
[N/A][552023752] Low CVE-2026-95316: Unchecked return value in Performance. Reported by Google on 2026-08-24
[N/A][553148673] Low CVE-2026-95328: Confused deputy in Mobile. Reported by Google on 2026-08-26
[N/A][553268567] Low CVE-2026-95340: Incorrect authorization in PictureInPicture. Reported by Google on 2026-08-27
[N/A][553271219] Low CVE-2026-95364: Improper input validation in Passwords. Reported by Google on 2026-08-27
[N/A][553921181] Low CVE-2026-95305: UI misrepresentation in Chromoting. Reported by Google on 2026-08-28
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.