Apple reports third quarter results


Today, we're taking a closer look at Sioux Falls, the largest city in South Dakota and one of the highlights of our upcoming South Dakota DLC for American Truck Simulator. Whether you're delivering cargo or simply enjoying the drive, this city offers plenty of memorable sights and destinations to explore. Let's take a closer look!
The Open Home Foundation fights for privacy, choice, and sustainability. These principles are at the heart of everything we do, including how we handle website analytics. Our position is clear: we reject tools that track individuals across the web to monetize their data. Instead, we want aggregated, anonymized analytics that show how our websites are performing overall — without identifying who our visitors are, or compromising their privacy.
Windows Installer
Windows No Installer (zip)
macOS - Universal
Linux - deb, AppImage or rpm
Windows intel x32 releases are marked -ia32-
ChangeLog:
The Stable channel has been updated to 151.0.7922.71/.72 for Windows and Mac and 151.0.7922.71 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 370 security fixes. Please see the Chrome Security Page for more information.
[N/A][514442821] Critical CVE-2026-17650: Use after free in Compositing. Reported by Google on 2026-05-18
[N/A][517307966] Critical CVE-2026-17651: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-05-28
[N/A][519262990] Critical CVE-2026-17652: Use after free in Views. Reported by Google on 2026-06-02
[N/A][520514458] Critical CVE-2026-17653: Use after free in Skia. Reported by Google on 2026-06-05
[N/A][522314940] Critical CVE-2026-17654: Race in Updater. Reported by Google on 2026-06-10
[N/A][522556145] Critical CVE-2026-17655: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-06-11
[N/A][523725277] Critical CVE-2026-17656: Use after free in Ozone. Reported by Google on 2026-06-14
[$36000][502293787] High CVE-2026-17657: Use after free in Navigation. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-14
[$1000][523030583] High CVE-2026-17658: Use after free in V8. Reported by Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security on 2026-06-12
[N/A][495463654] High CVE-2026-17659: Inappropriate implementation in SiteIsolation. Reported by Google on 2026-03-23
[N/A][497428001] High CVE-2026-17660: Insufficient validation of untrusted input in Network. Reported by Google on 2026-03-29
[N/A][497451790] High CVE-2026-17661: Use after free in Loader. Reported by Google on 2026-03-29
[N/A][497491557] High CVE-2026-17662: Insufficient policy enforcement in Prefetch. Reported by Google on 2026-03-29
[N/A][500225310] High CVE-2026-17663: Insufficient validation of untrusted input in GPU. Reported by Google on 2026-04-07
[N/A][500554346] High CVE-2026-17664: Insufficient validation of untrusted input in Loader. Reported by Google on 2026-04-08
[N/A][511277457] High CVE-2026-17665: Use after free in V8. Reported by Google on 2026-05-08
[N/A][511761758] High CVE-2026-17666: Cryptographic Flaw in Enterprise. Reported by Google on 2026-05-10
[N/A][513043537] High CVE-2026-17667: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14
[N/A][513134019] High CVE-2026-17668: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14
[N/A][513142464] High CVE-2026-17669: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-14
[N/A][513228974] High CVE-2026-17670: Use after free in Views. Reported by Google on 2026-05-14
[N/A][513257423] High CVE-2026-17671: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-14
[N/A][513375270] High CVE-2026-17672: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-05-15
[N/A][513735177] High CVE-2026-17673: Integer overflow in QUIC. Reported by Google on 2026-05-16
[N/A][513791232] High CVE-2026-17674: Inappropriate implementation in HTML. Reported by Google on 2026-05-16
[N/A][513920258] High CVE-2026-17675: Out of bounds write in ANGLE. Reported by Google on 2026-05-17
[N/A][513920298] High CVE-2026-17676: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17
[N/A][513921488] High CVE-2026-17677: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17
[N/A][515452019] High CVE-2026-17678: Out of bounds read in ANGLE. Reported by Google on 2026-05-21
[N/A][516430649] High CVE-2026-17679: Insufficient validation of untrusted input in Print Preview. Reported by Google on 2026-05-25
[N/A][516486611] High CVE-2026-17680: Heap buffer overflow in Color. Reported by Google on 2026-05-25
[N/A][516813184] High CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication. Reported by Google on 2026-05-26
[N/A][516837126] High CVE-2026-17682: Integer overflow in ANGLE. Reported by Google on 2026-05-26
[N/A][516887576] High CVE-2026-17683: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-26
[N/A][516894682] High CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-26
[N/A][516910278] High CVE-2026-17685: Use after free in Autofill. Reported by Google on 2026-05-27
[N/A][516917065] High CVE-2026-17686: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-27
[N/A][516985726] High CVE-2026-17687: Type Confusion in ANGLE. Reported by Google on 2026-05-27
[N/A][517016413] High CVE-2026-17688: Use after free in Input. Reported by Google on 2026-05-27
[N/A][517045160] High CVE-2026-17689: Uninitialized Use in ANGLE. Reported by Google on 2026-05-27
[N/A][517129282] High CVE-2026-17690: Insufficient validation of untrusted input in PDF. Reported by Google on 2026-05-27
[N/A][517321292] High CVE-2026-17691: Out of bounds write in ANGLE. Reported by Google on 2026-05-28
[N/A][517350808] High CVE-2026-17692: Use after free in DataTransfer. Reported by Google on 2026-05-28
[N/A][517448723] High CVE-2026-17693: Inappropriate implementation in FileSystem. Reported by Google on 2026-05-28
[N/A][517511796] High CVE-2026-17694: Use after free in DOM. Reported by Google on 2026-05-28
[N/A][517543052] High CVE-2026-17695: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-28
[N/A][517550034] High CVE-2026-17696: Side-channel information leakage in Media. Reported by Google on 2026-05-28
[N/A][517575864] High CVE-2026-17697: Type Confusion in ANGLE. Reported by Google on 2026-05-28
[N/A][517670731] High CVE-2026-17698: Insufficient validation of untrusted input in UI. Reported by Google on 2026-05-29
[N/A][517785292] High CVE-2026-17699: Use after free in Views. Reported by Google on 2026-05-29
[N/A][517789833] High CVE-2026-17700: Insufficient validation of untrusted input in Actor. Reported by Google on 2026-05-29
[N/A][517972648] High CVE-2026-17701: Out of bounds read in ANGLE. Reported by Google on 2026-05-29
[N/A][517973093] High CVE-2026-17702: Inappropriate implementation in Skia. Reported by Google on 2026-05-29
[N/A][518051499] High CVE-2026-17703: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][519259107] High CVE-2026-17704: Use after free in ANGLE. Reported by Google on 2026-06-02
[TBD][519665978] High CVE-2026-17705: Integer overflow in libxml. Reported by ebassi of Igalia on 2026-06-04
[N/A][519693032] High CVE-2026-17706: Insufficient validation of untrusted input in Media. Reported by Google on 2026-06-03
[N/A][519701233] High CVE-2026-17707: Uninitialized Use in Media. Reported by Google on 2026-06-03
[N/A][519738647] High CVE-2026-17708: Use after free in Audio. Reported by Google on 2026-06-04
[N/A][519981494] High CVE-2026-17709: Race in Downloads. Reported by Google on 2026-06-04
[N/A][519991712] High CVE-2026-17710: Inappropriate implementation in MHTML. Reported by Google on 2026-06-04
[N/A][519996040] High CVE-2026-17711: Race in Downloads. Reported by Google on 2026-06-04
[N/A][520535595] High CVE-2026-17712: Race in Skia. Reported by Google on 2026-06-05
[N/A][520572766] High CVE-2026-17713: Insufficient validation of untrusted input in Accessibility. Reported by Google on 2026-06-06
[N/A][521293438] High CVE-2026-17714: Uninitialized Use in ANGLE. Reported by Google on 2026-06-08
[N/A][521491778] High CVE-2026-17715: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08
[N/A][521866061] High CVE-2026-17716: Use after free in Updater. Reported by Google on 2026-06-09
[N/A][522063116] High CVE-2026-17717: Integer overflow in ANGLE. Reported by Google on 2026-06-10
[N/A][522079372] High CVE-2026-17718: Use after free in ANGLE. Reported by Google on 2026-06-10
[N/A][522304853] High CVE-2026-17719: Use after free in Input. Reported by Google on 2026-06-10
[N/A][522545249] High CVE-2026-17720: Insufficient policy enforcement in Passwords. Reported by Google on 2026-06-11
[N/A][523495723] High CVE-2026-17721: Out of bounds write in ANGLE. Reported by Google on 2026-06-13
[N/A][523592755] High CVE-2026-17722: Object lifecycle issue in WebView. Reported by Google on 2026-06-13
[N/A][523718303] High CVE-2026-17723: Use after free in Media. Reported by Google on 2026-06-14
[N/A][523720739] High CVE-2026-17724: Race in Chrome for iOS. Reported by Google on 2026-06-14
[TBD][528501127] High CVE-2026-17725: Type Confusion in V8. Reported by nh.dev2022 on 2026-06-27
[N/A][529867799] High CVE-2026-17726: Integer overflow in WebGL. Reported by Google on 2026-06-30
[N/A][529932631] High CVE-2026-17727: Out of bounds write in WebGL. Reported by Google on 2026-07-01
[$10000][461167648] Medium CVE-2026-17728: Inappropriate implementation in Extensions. Reported by Suhas S P on 2025-11-16
[$5000][503801946] Medium CVE-2026-17758: Heap buffer overflow in Dawn. Reported by Hyeonjun Ahn (@_deayzl) on 2026-04-18
[$2000][476646486] Medium CVE-2026-17732: Inappropriate implementation in SVG. Reported by Lyra Rebane (rebane2001) on 2026-01-17
[$500][520656237] Medium CVE-2026-17729: Use after free in V8. Reported by wang1r && lhfff on 2026-06-07
[N/A][40057032] Medium CVE-2026-17730: Side-channel information leakage in Autofill. Reported by Google on 2021-08-26
[TBD][463551850] Medium CVE-2026-17731: Inappropriate implementation in Autofill. Reported by Manojkumar Jaganathan Aka TheWhiteEvil with HackerBro Technologies on 2025-11-25
[N/A][495793059] Medium CVE-2026-17733: Inappropriate implementation in QUIC. Reported by Google on 2026-03-24
[N/A][496304083] Medium CVE-2026-17734: Inappropriate implementation in Autofill. Reported by Google on 2026-03-25
[N/A][496569497] Medium CVE-2026-17735: Insufficient validation of untrusted input in BFCache. Reported by Google on 2026-03-26
[N/A][496715442] Medium CVE-2026-17736: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-03-27
[N/A][498000415] Medium CVE-2026-17737: Use after free in Bluetooth. Reported by Google on 2026-03-31
[N/A][498079379] Medium CVE-2026-17738: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-03-31
[N/A][498353463] Medium CVE-2026-17739: Insufficient policy enforcement in Extensions. Reported by Google on 2026-03-31
[N/A][498827800] Medium CVE-2026-17740: Uninitialized Use in ANGLE. Reported by Google on 2026-04-02
[N/A][498877660] Medium CVE-2026-17741: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-04-02
[N/A][499003233] Medium CVE-2026-17742: Insufficient policy enforcement in Payments. Reported by Google on 2026-04-02
[N/A][499204022] Medium CVE-2026-17743: Insufficient policy enforcement in ControlledFrame. Reported by Google on 2026-04-03
[N/A][500137309] Medium CVE-2026-17744: Inappropriate implementation in File Input. Reported by Google on 2026-04-07
[N/A][500172224] Medium CVE-2026-17745: Out of bounds read in Skia. Reported by Google on 2026-04-07
[N/A][500390256] Medium CVE-2026-17746: Use after free in GPU. Reported by Google on 2026-04-07
[N/A][500472958] Medium CVE-2026-17747: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-04-07
[N/A][500494349] Medium CVE-2026-17748: Inappropriate implementation in Extensions. Reported by Google on 2026-04-08
[N/A][500526602] Medium CVE-2026-17749: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-04-08
[N/A][500560234] Medium CVE-2026-17750: Use after free in ANGLE. Reported by Google on 2026-04-08
[N/A][501591293] Medium CVE-2026-17751: Inappropriate implementation in AdFilter. Reported by Google on 2026-04-11
[N/A][501619207] Medium CVE-2026-17752: Use after free in Views. Reported by Google on 2026-04-11
[N/A][501628355] Medium CVE-2026-17753: Inappropriate implementation in Autofill. Reported by Google on 2026-04-11
[N/A][501675996] Medium CVE-2026-17754: Inappropriate implementation in Blink. Reported by Google on 2026-04-11
[N/A][501854535] Medium CVE-2026-17755: Incorrect security UI in Extensions. Reported by Google on 2026-04-12
[N/A][501980797] Medium CVE-2026-17756: Insufficient policy enforcement in Presentation. Reported by Google on 2026-04-13
[N/A][502351526] Medium CVE-2026-17757: Uninitialized Use in Skia. Reported by Google on 2026-04-14
[N/A][504650654] Medium CVE-2026-17759: Uninitialized Use in Codecs. Reported by Google on 2026-04-20
[N/A][506473189] Medium CVE-2026-17760: Side-channel information leakage in NoStatePrefetch. Reported by Google on 2026-04-25
[N/A][508249524] Medium CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-04-30
[N/A][508251844] Medium CVE-2026-17762: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-30
[N/A][511738693] Medium CVE-2026-17763: Inappropriate implementation in GPU. Reported by Google on 2026-05-10
[N/A][511754400] Medium CVE-2026-17764: Inappropriate implementation in FedCM. Reported by Google on 2026-05-10
[N/A][511765328] Medium CVE-2026-17765: Inappropriate implementation in WebProtect. Reported by Google on 2026-05-10
[N/A][511799537] Medium CVE-2026-17766: Insufficient validation of untrusted input in Clipboard. Reported by Google on 2026-05-10
[N/A][511822402] Medium CVE-2026-17767: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-05-10
[N/A][512999037] Medium CVE-2026-17768: Insufficient validation of untrusted input in WebSockets. Reported by Google on 2026-05-13
[N/A][513022076] Medium CVE-2026-17769: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14
[N/A][513103345] Medium CVE-2026-17770: Out of bounds read in Media. Reported by Google on 2026-05-14
[N/A][513160525] Medium CVE-2026-17771: Uninitialized Use in Skia. Reported by Google on 2026-05-14
[N/A][513197846] Medium CVE-2026-17772: Out of bounds read in WebGL. Reported by Google on 2026-05-14
[N/A][513232523] Medium CVE-2026-17773: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14
[N/A][513323066] Medium CVE-2026-17774: Insufficient validation of untrusted input in Variations. Reported by Google on 2026-05-14
[N/A][513363822] Medium CVE-2026-17775: Inappropriate implementation in PresentationAPI. Reported by Google on 2026-05-15
[N/A][513404032] Medium CVE-2026-17776: Policy bypass in Receiver. Reported by Google on 2026-05-15
[N/A][513462236] Medium CVE-2026-17777: Inappropriate implementation in Autofill. Reported by Google on 2026-05-15
[N/A][513467993] Medium CVE-2026-17778: Use after free in Extensions. Reported by Google on 2026-05-15
[N/A][513478933] Medium CVE-2026-17779: Inappropriate implementation in Site Isolation. Reported by Google on 2026-05-15
[N/A][513485951] Medium CVE-2026-17780: Inappropriate implementation in Isolated Web Apps. Reported by Google on 2026-05-15
[N/A][513502990] Medium CVE-2026-17781: Inappropriate implementation in Extensions. Reported by Google on 2026-05-15
[N/A][513507830] Medium CVE-2026-17782: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-15
[N/A][513532735] Medium CVE-2026-17783: Inappropriate implementation in Loader. Reported by Google on 2026-05-15
[N/A][513694032] Medium CVE-2026-17784: Use after free in Audio. Reported by Google on 2026-05-16
[N/A][513769898] Medium CVE-2026-17785: Uninitialized Use in ANGLE. Reported by Google on 2026-05-16
[N/A][513770449] Medium CVE-2026-17786: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16
[N/A][513783632] Medium CVE-2026-17787: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16
[N/A][513824957] Medium CVE-2026-17788: Inappropriate implementation in Blink. Reported by Google on 2026-05-16
[N/A][513855922] Medium CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-16
[N/A][513919931] Medium CVE-2026-17790: Uninitialized Use in ANGLE. Reported by Google on 2026-05-17
[N/A][514006959] Medium CVE-2026-17791: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-17
[N/A][514019823] Medium CVE-2026-17792: Inappropriate implementation in Credential Management. Reported by Google on 2026-05-17
[N/A][514063859] Medium CVE-2026-17793: Inappropriate implementation in Messages. Reported by Google on 2026-05-17
[N/A][514067070] Medium CVE-2026-17794: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-05-17
[TBD][514242889] Medium CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia. Reported by Mihnea Nicolau on 2026-05-18
[N/A][514427844] Medium CVE-2026-17796: Side-channel information leakage in WebXR. Reported by Google on 2026-05-18
[N/A][514441966] Medium CVE-2026-17797: Inappropriate implementation in CSS. Reported by Google on 2026-05-18
[N/A][514460133] Medium CVE-2026-17798: Inappropriate implementation in Cast. Reported by Google on 2026-05-19
[N/A][514461031] Medium CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing. Reported by Google on 2026-05-19
[N/A][514480948] Medium CVE-2026-17800: Side-channel information leakage in MediaRecording. Reported by Google on 2026-05-19
[N/A][514482938] Medium CVE-2026-17801: Out of bounds memory access in ANGLE. Reported by Google on 2026-05-19
[N/A][514512198] Medium CVE-2026-17802: Side-channel information leakage in GPU. Reported by Google on 2026-05-19
[N/A][515438919] Medium CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive. Reported by Google on 2026-05-21
[N/A][515448947] Medium CVE-2026-17804: Use after free in Media. Reported by Google on 2026-05-21
[N/A][516420806] Medium CVE-2026-17805: Insufficient policy enforcement in Glic. Reported by Google on 2026-05-25
[N/A][516433058] Medium CVE-2026-17806: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-25
[N/A][516763884] Medium CVE-2026-17807: Use after free in V8. Reported by Google on 2026-05-26
[N/A][516778390] Medium CVE-2026-17808: Uninitialized Use in WebGL. Reported by Google on 2026-05-26
[N/A][516813317] Medium CVE-2026-17809: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-26
[N/A][516882109] Medium CVE-2026-17810: Uninitialized Use in Dawn. Reported by Google on 2026-05-26
[N/A][516954622] Medium CVE-2026-17811: Use after free in ANGLE. Reported by Google on 2026-05-27
[N/A][517101596] Medium CVE-2026-17812: Inappropriate implementation in DigitalCredentials. Reported by Google on 2026-05-27
[N/A][517184957] Medium CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-05-27
[N/A][517312048] Medium CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-28
[N/A][517427352] Medium CVE-2026-17815: Insufficient policy enforcement in GuestView. Reported by Google on 2026-05-28
[N/A][517429672] Medium CVE-2026-17816: Inappropriate implementation in Speech. Reported by Google on 2026-05-28
[N/A][517461759] Medium CVE-2026-17817: Inappropriate implementation in ReportingAndNEL. Reported by Google on 2026-05-28
[N/A][517466133] Medium CVE-2026-17818: Inappropriate implementation in Network. Reported by Google on 2026-05-28
[N/A][517487028] Medium CVE-2026-17819: Inappropriate implementation in WebAppInstalls. Reported by Google on 2026-05-28
[N/A][517493101] Medium CVE-2026-17820: Insufficient policy enforcement in Autofill. Reported by Google on 2026-05-28
[N/A][517597914] Medium CVE-2026-17821: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-28
[N/A][517621178] Medium CVE-2026-17822: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28
[N/A][517628043] Medium CVE-2026-17823: Insufficient policy enforcement in WebXR. Reported by Google on 2026-05-28
[N/A][517655543] Medium CVE-2026-17824: Insufficient policy enforcement in ServiceWorker. Reported by Google on 2026-05-28
[N/A][517675979] Medium CVE-2026-17825: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29
[N/A][517690521] Medium CVE-2026-17826: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29
[N/A][517693726] Medium CVE-2026-17827: Inappropriate implementation in CSS. Reported by Google on 2026-05-29
[N/A][517702279] Medium CVE-2026-17828: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29
[N/A][517705103] Medium CVE-2026-17829: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29
[N/A][517710397] Medium CVE-2026-17830: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29
[N/A][517714728] Medium CVE-2026-17831: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-29
[N/A][517723319] Medium CVE-2026-17832: Use after free in ANGLE. Reported by Google on 2026-05-29
[N/A][517779123] Medium CVE-2026-17833: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29
[N/A][517793801] Medium CVE-2026-17834: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29
[N/A][517801739] Medium CVE-2026-17835: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29
[TBD][517972812] Medium CVE-2026-17836: Use after free in V8. Reported by yupyon.itome on 2026-05-30
[N/A][517978932] Medium CVE-2026-17837: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-29
[N/A][518075952] Medium CVE-2026-17838: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518080978] Medium CVE-2026-17839: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518082162] Medium CVE-2026-17840: Incorrect security UI in Passwords. Reported by Google on 2026-05-30
[N/A][518088219] Medium CVE-2026-17841: Race in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518089997] Medium CVE-2026-17842: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518103887] Medium CVE-2026-17843: Inappropriate implementation in CSS. Reported by Google on 2026-05-30
[N/A][518111542] Medium CVE-2026-17844: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-30
[N/A][518112775] Medium CVE-2026-17845: Inappropriate implementation in CSS. Reported by Google on 2026-05-30
[N/A][518121320] Medium CVE-2026-17846: Inappropriate implementation in Media. Reported by Google on 2026-05-30
[N/A][518243653] Medium CVE-2026-17847: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-30
[TBD][518284253] Medium CVE-2026-17848: Insufficient validation of untrusted input in Codecs. Reported by Ameen Basha M K on 2026-05-31
[N/A][518812672] Medium CVE-2026-17849: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-01
[TBD][519078527] Medium CVE-2026-17850: Inappropriate implementation in Permissions. Reported by Tech Division (@taiphung) - Mobifone Digital Payment on 2026-06-02
[N/A][519243927] Medium CVE-2026-17851: Side-channel information leakage in Autofill. Reported by Google on 2026-06-02
[N/A][519348818] Medium CVE-2026-17852: Inappropriate implementation in Media Router. Reported by Google on 2026-06-03
[TBD][519472272] Medium CVE-2026-17853: Inappropriate implementation in DevTools. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-06-03
[N/A][519500882] Medium CVE-2026-17854: Insufficient policy enforcement in WebMCP. Reported by Google on 2026-06-03
[N/A][519982572] Medium CVE-2026-17855: Race in DevTools. Reported by Google on 2026-06-04
[N/A][519991751] Medium CVE-2026-17856: Inappropriate implementation in Network. Reported by Google on 2026-06-04
[N/A][520186620] Medium CVE-2026-17857: Inappropriate implementation in Network. Reported by Google on 2026-06-05
[N/A][520191468] Medium CVE-2026-17858: Uninitialized Use in WebNN. Reported by Google on 2026-06-05
[N/A][520196753] Medium CVE-2026-17859: Side-channel information leakage in Favicons. Reported by Google on 2026-06-05
[N/A][520407381] Medium CVE-2026-17860: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-06-05
[N/A][520417861] Medium CVE-2026-17861: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-05
[N/A][520426287] Medium CVE-2026-17862: Use after free in Tracing. Reported by Google on 2026-06-05
[N/A][520468718] Medium CVE-2026-17863: Inappropriate implementation in Browser. Reported by Google on 2026-06-05
[N/A][520494861] Medium CVE-2026-17864: Inappropriate implementation in Updater. Reported by Google on 2026-06-05
[N/A][520516655] Medium CVE-2026-17865: Inappropriate implementation in Crypto. Reported by Google on 2026-06-05
[N/A][520525732] Medium CVE-2026-17866: Type Confusion in Tab. Reported by Google on 2026-06-05
[N/A][520527496] Medium CVE-2026-17867: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-06-05
[TBD][520743499] Medium CVE-2026-17868: Insufficient policy enforcement in USB. Reported by Ariel Simon on 2026-06-06
[N/A][521759269] Medium CVE-2026-17869: Out of bounds read in WebXR. Reported by Google on 2026-06-09
[N/A][521784856] Medium CVE-2026-17870: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-09
[N/A][521938924] Medium CVE-2026-17871: Inappropriate implementation in Passwords. Reported by Google on 2026-06-09
[N/A][521963740] Medium CVE-2026-17872: Cryptographic Flaw in WebAppInstalls. Reported by Google on 2026-06-09
[N/A][522074033] Medium CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-10
[N/A][522074154] Medium CVE-2026-17874: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-10
[N/A][522299155] Medium CVE-2026-17875: Use after free in PDFium. Reported by Google on 2026-06-10
[N/A][522425471] Medium CVE-2026-17876: Inappropriate implementation in Payments. Reported by Google on 2026-06-10
[N/A][522426086] Medium CVE-2026-17877: Inappropriate implementation in Chromoting. Reported by Google on 2026-06-10
[N/A][522781838] Medium CVE-2026-17878: Inappropriate implementation in CSS. Reported by Google on 2026-06-11
[N/A][522878450] Medium CVE-2026-17879: Inappropriate implementation in Autofill. Reported by Google on 2026-06-11
[N/A][523229759] Medium CVE-2026-17880: Inappropriate implementation in Autofill. Reported by Google on 2026-06-12
[N/A][523477987] Medium CVE-2026-17881: Use after free in WebXR. Reported by Google on 2026-06-13
[N/A][523637452] Medium CVE-2026-17882: Policy bypass in Extensions. Reported by Google on 2026-06-13
[N/A][523639090] Medium CVE-2026-17883: Inappropriate implementation in Headless. Reported by Google on 2026-06-13
[N/A][523692228] Medium CVE-2026-17884: Object lifecycle issue in WebRTC. Reported by Google on 2026-06-13
[N/A][523698038] Medium CVE-2026-17885: Inappropriate implementation in Paint. Reported by Google on 2026-06-13
[N/A][523715964] Medium CVE-2026-17886: Use after free in Enterprise. Reported by Google on 2026-06-14
[N/A][523717010] Medium CVE-2026-17887: Use after free in TabStrip. Reported by Google on 2026-06-14
[N/A][523720529] Medium CVE-2026-17888: Insufficient validation of untrusted input in WebUI. Reported by Google on 2026-06-14
[N/A][523735357] Medium CVE-2026-17889: Uninitialized Use in WebXR. Reported by Google on 2026-06-14
[N/A][524029061] Medium CVE-2026-17890: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-15
[N/A][524639223] Medium CVE-2026-17891: Use after free in ANGLE. Reported by Google on 2026-06-16
[N/A][524822998] Medium CVE-2026-17892: Inappropriate implementation in WebXR. Reported by Google on 2026-06-17
[N/A][524824730] Medium CVE-2026-17893: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-17
[N/A][524825209] Medium CVE-2026-17894: Use after free in Views. Reported by Google on 2026-06-17
[TBD][524931675] Medium CVE-2026-17895: Inappropriate implementation in DataTransfer. Reported by hongan@calif.io on 2026-06-17
[N/A][525331547] Medium CVE-2026-17896: Use after free in DevTools. Reported by Google on 2026-06-18
[TBD][527665262] Medium CVE-2026-17897: Inappropriate implementation in ORB. Reported by Sharkkcode on 2026-06-25
[$3000][506193577] Low CVE-2026-17898: Use after free in DevTools. Reported by Syn4pse on 2026-04-24
[$1000][375959766] Low CVE-2026-17899: Insufficient policy enforcement in DevTools. Reported by asnine on 2024-10-28
[N/A][496195854] Low CVE-2026-17900: Inappropriate implementation in Enterprise. Reported by Google on 2026-03-25
[N/A][496271098] Low CVE-2026-17901: Inappropriate implementation in Sharing. Reported by Google on 2026-03-25
[N/A][497251066] Low CVE-2026-17902: Inappropriate implementation in Editing. Reported by Google on 2026-03-28
[N/A][497277880] Low CVE-2026-17903: Insufficient policy enforcement in Chromecast. Reported by Google on 2026-03-28
[N/A][497337759] Low CVE-2026-17904: Insufficient policy enforcement in NFC. Reported by Google on 2026-03-29
[N/A][497366217] Low CVE-2026-17905: Inappropriate implementation in SurfaceCapture. Reported by Google on 2026-03-29
[N/A][497654761] Low CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth. Reported by Google on 2026-03-30
[N/A][497837927] Low CVE-2026-17907: Side-channel information leakage in Network. Reported by Google on 2026-03-30
[N/A][499062890] Low CVE-2026-17908: Insufficient validation of untrusted input in Printing. Reported by Google on 2026-04-02
[N/A][501693236] Low CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps. Reported by Google on 2026-04-11
[N/A][501749600] Low CVE-2026-17910: Insufficient policy enforcement in NFC. Reported by Google on 2026-04-11
[N/A][502505715] Low CVE-2026-17911: Insufficient policy enforcement in SVG. Reported by Google on 2026-04-14
[N/A][504202939] Low CVE-2026-17912: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19
[N/A][504209246] Low CVE-2026-17913: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19
[N/A][506377118] Low CVE-2026-17914: Side-channel information leakage in Skia. Reported by Google on 2026-04-25
[N/A][506390325] Low CVE-2026-17915: Inappropriate implementation in WebView. Reported by Google on 2026-04-25
[TBD][510808598] Low CVE-2026-17916: Insufficient policy enforcement in Settings. Reported by Itzik Chimino on 2026-05-07
[N/A][511816897] Low CVE-2026-17917: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-10
[N/A][513127137] Low CVE-2026-17918: Use after free in Sync. Reported by Google on 2026-05-14
[N/A][513291747] Low CVE-2026-17919: Insufficient policy enforcement in Enterprise. Reported by Google on 2026-05-14
[N/A][513413942] Low CVE-2026-17920: Use after free in V8. Reported by Google on 2026-05-15
[N/A][513503197] Low CVE-2026-17921: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-05-15
[N/A][513611659] Low CVE-2026-17922: Inappropriate implementation in Enterprise. Reported by Google on 2026-05-15
[N/A][513612928] Low CVE-2026-17923: Policy bypass in Enterprise. Reported by Google on 2026-05-15
[N/A][513714124] Low CVE-2026-17924: Use after free in DNS. Reported by Google on 2026-05-16
[N/A][513719671] Low CVE-2026-17925: Inappropriate implementation in Cast. Reported by Google on 2026-05-16
[N/A][513735900] Low CVE-2026-17926: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16
[N/A][513754837] Low CVE-2026-17927: Insufficient policy enforcement in DevTools. Reported by Google on 2026-05-16
[N/A][513762372] Low CVE-2026-17928: Inappropriate implementation in DataTransfer. Reported by Google on 2026-05-16
[N/A][513768645] Low CVE-2026-17929: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16
[N/A][513769158] Low CVE-2026-17930: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-16
[N/A][513781245] Low CVE-2026-17931: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16
[N/A][513819157] Low CVE-2026-17932: Use after free in DataTransfer. Reported by Google on 2026-05-16
[N/A][513822044] Low CVE-2026-17933: Inappropriate implementation in DOMStorage. Reported by Google on 2026-05-16
[N/A][513838421] Low CVE-2026-17934: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16
[N/A][513863267] Low CVE-2026-17935: Heap buffer overflow in Codecs. Reported by Google on 2026-05-16
[N/A][513864014] Low CVE-2026-17936: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16
[N/A][513866380] Low CVE-2026-17937: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16
[N/A][513989304] Low CVE-2026-17938: Inappropriate implementation in FullScreen. Reported by Google on 2026-05-17
[N/A][514060089] Low CVE-2026-17939: Inappropriate implementation in Passwords. Reported by Google on 2026-05-17
[N/A][514069440] Low CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture. Reported by Google on 2026-05-17
[N/A][514147906] Low CVE-2026-17941: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-18
[N/A][514406198] Low CVE-2026-17942: Side-channel information leakage in SVG. Reported by Google on 2026-05-18
[N/A][514424283] Low CVE-2026-17943: Inappropriate implementation in Parser. Reported by Google on 2026-05-18
[N/A][514510853] Low CVE-2026-17944: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-19
[N/A][514519203] Low CVE-2026-17945: Inappropriate implementation in Navigation. Reported by Google on 2026-05-19
[N/A][515437522] Low CVE-2026-17946: Uninitialized Use in Dawn. Reported by Google on 2026-05-21
[N/A][515438256] Low CVE-2026-17947: Use after free in WebSockets. Reported by Google on 2026-05-21
[N/A][516849257] Low CVE-2026-17948: Type Confusion in V8. Reported by Google on 2026-05-26
[N/A][517000034] Low CVE-2026-17949: Uninitialized Use in GPU. Reported by Google on 2026-05-27
[N/A][517063658] Low CVE-2026-17950: Policy bypass in Safebrowsing. Reported by Google on 2026-05-27
[N/A][517180511] Low CVE-2026-17951: Heap buffer overflow in WebRTC. Reported by Google on 2026-05-27
[N/A][517316174] Low CVE-2026-17952: Inappropriate implementation in V8. Reported by Google on 2026-05-28
[N/A][517335150] Low CVE-2026-17953: Insufficient policy enforcement in WebView. Reported by Google on 2026-05-28
[N/A][517383492] Low CVE-2026-17954: Policy bypass in MHTML. Reported by Google on 2026-05-28
[N/A][517385072] Low CVE-2026-17955: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-28
[N/A][517436171] Low CVE-2026-17956: Inappropriate implementation in Scheduling. Reported by Google on 2026-05-28
[N/A][517476342] Low CVE-2026-17957: Inappropriate implementation in CORS. Reported by Google on 2026-05-28
[N/A][517538206] Low CVE-2026-17958: Inappropriate implementation in Views. Reported by Google on 2026-05-28
[N/A][517607890] Low CVE-2026-17959: Inappropriate implementation in Network. Reported by Google on 2026-05-28
[N/A][517631680] Low CVE-2026-17960: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28
[N/A][517700791] Low CVE-2026-17961: Inappropriate implementation in Session. Reported by Google on 2026-05-29
[N/A][517757268] Low CVE-2026-17962: Inappropriate implementation in Blink. Reported by Google on 2026-05-29
[N/A][517759257] Low CVE-2026-17963: Inappropriate implementation in SVG. Reported by Google on 2026-05-29
[N/A][518025103] Low CVE-2026-17964: Incorrect security UI in UI. Reported by Google on 2026-05-29
[N/A][518049812] Low CVE-2026-17965: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518058990] Low CVE-2026-17966: Inappropriate implementation in Views. Reported by Google on 2026-05-30
[N/A][518243858] Low CVE-2026-17967: Use after free in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518337516] Low CVE-2026-17968: Uninitialized Use in WebXR. Reported by Google on 2026-05-31
[N/A][518812295] Low CVE-2026-17969: Inappropriate implementation in Passwords. Reported by Google on 2026-06-01
[N/A][518814464] Low CVE-2026-17970: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-01
[N/A][518815075] Low CVE-2026-17971: Inappropriate implementation in Frame. Reported by Google on 2026-06-01
[N/A][519202895] Low CVE-2026-17972: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-02
[N/A][519230894] Low CVE-2026-17973: Inappropriate implementation in Views. Reported by Google on 2026-06-02
[N/A][519232592] Low CVE-2026-17974: Insufficient policy enforcement in DevTools. Reported by Google on 2026-06-02
[N/A][519233776] Low CVE-2026-17975: Inappropriate implementation in IME. Reported by Google on 2026-06-02
[N/A][519455164] Low CVE-2026-17976: Policy bypass in Extensions. Reported by Google on 2026-06-03
[N/A][519603552] Low CVE-2026-17977: Policy bypass in CSS. Reported by Google on 2026-06-03
[N/A][519610845] Low CVE-2026-17978: Side-channel information leakage in WebCodecs. Reported by Google on 2026-06-03
[N/A][519664497] Low CVE-2026-17979: Race in V8. Reported by Google on 2026-06-04
[N/A][519710361] Low CVE-2026-17980: Inappropriate implementation in UI. Reported by Google on 2026-06-03
[N/A][519719512] Low CVE-2026-17981: Inappropriate implementation in Blink. Reported by Google on 2026-06-03
[N/A][519735808] Low CVE-2026-17982: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-04
[N/A][519744561] Low CVE-2026-17983: Incorrect security UI in Global Media Controls. Reported by Google on 2026-06-04
[N/A][519978460] Low CVE-2026-17984: Inappropriate implementation in Browser. Reported by Google on 2026-06-04
[N/A][519981430] Low CVE-2026-17985: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-04
[N/A][519981896] Low CVE-2026-17986: Insufficient policy enforcement in Bluetooth. Reported by Google on 2026-06-04
[N/A][519988071] Low CVE-2026-17987: Insufficient validation of untrusted input in Notifications. Reported by Google on 2026-06-04
[N/A][520005624] Low CVE-2026-17988: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-06-04
[N/A][520017306] Low CVE-2026-17989: Type Confusion in V8. Reported by Google on 2026-06-04
[N/A][520018012] Low CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn. Reported by Google on 2026-06-04
[N/A][520110535] Low CVE-2026-17991: Insufficient validation of untrusted input in AI. Reported by Google on 2026-06-04
[N/A][520506316] Low CVE-2026-17992: Uninitialized Use in Skia. Reported by Google on 2026-06-05
[N/A][520532191] Low CVE-2026-17993: Race in Updater. Reported by Google on 2026-06-05
[N/A][520663771] Low CVE-2026-17994: Inappropriate implementation in Media. Reported by Google on 2026-06-06
[TBD][520972775] Low CVE-2026-17995: Out of bounds read in Dawn. Reported by sm1ee, ksw9722 on 2026-06-07
[N/A][521473427] Low CVE-2026-17996: Inappropriate implementation in Browser. Reported by Google on 2026-06-08
[N/A][521476960] Low CVE-2026-17997: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08
[N/A][521601450] Low CVE-2026-17998: Incorrect security UI in Extensions. Reported by Google on 2026-06-09
[N/A][521615681] Low CVE-2026-17999: Incorrect security UI in PictureInPicture. Reported by Google on 2026-06-09
[N/A][521623907] Low CVE-2026-18000: Insufficient policy enforcement in USB. Reported by Google on 2026-06-09
[N/A][521757779] Low CVE-2026-18001: Inappropriate implementation in WebGL. Reported by Google on 2026-06-09
[N/A][521864362] Low CVE-2026-18002: Insufficient validation of untrusted input in Google Lens. Reported by Google on 2026-06-09
[N/A][521934304] Low CVE-2026-18003: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-09
[N/A][522280805] Low CVE-2026-18004: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-10
[N/A][522300211] Low CVE-2026-18005: Inappropriate implementation in WebXR. Reported by Google on 2026-06-10
[N/A][522396262] Low CVE-2026-18006: Inappropriate implementation in Google Lens. Reported by Google on 2026-06-10
[N/A][522404101] Low CVE-2026-18007: Inappropriate implementation in Input. Reported by Google on 2026-06-10
[N/A][522412676] Low CVE-2026-18008: Inappropriate implementation in Settings. Reported by Google on 2026-06-10
[N/A][522419718] Low CVE-2026-18009: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-10
[N/A][522419819] Low CVE-2026-18010: Inappropriate implementation in Passwords. Reported by Google on 2026-06-10
[N/A][522479633] Low CVE-2026-18011: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-11
[N/A][522938824] Low CVE-2026-18012: Use after free in PDFium. Reported by Google on 2026-06-11
[N/A][523245998] Low CVE-2026-18013: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-12
[N/A][523248021] Low CVE-2026-18014: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-12
[N/A][523698428] Low CVE-2026-18015: Inappropriate implementation in Tint. Reported by Google on 2026-06-13
[N/A][523708527] Low CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-13
[N/A][523731236] Low CVE-2026-18017: Use after free in Dawn. Reported by Google on 2026-06-14
[N/A][524467747] Low CVE-2026-18018: Inappropriate implementation in Updater. Reported by Google on 2026-06-16
[N/A][525691898] Low CVE-2026-18019: Side-channel information leakage in Media. Reported by Google on 2026-06-19
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.
Krishna Govind
Google Chrome
![]()
Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields (#27996)
The minimal app permissions now grant read access to only a subset of directus_settings fields. This applies to new policies, existing policies are untouched.
Replaced the TinyMCE editor powering the WYSIWYG with Tiptap... (#27754)
The WYSIWYG interface now runs on Tiptap instead of TinyMCE
tinymceOverrides no longer has any effect. Stored values are kept and a console warning is logged, but the editor ignores them. Use the fontsize/fontfamily toolbar menus and customFormats instead.tinymce object) no longer applies.Fixed deployment webhooks resolving a project from the wrong provider when external IDs collide (#27816)
The DeploymentProjectsService.readByExternalId method now takes the deployment ID as its first argument (i.e. readByExternalId(deploymentId, externalId))
Added support for multi-collection flat data imports (#27984)
Import file size is now capped by default
A new IMPORT_MAX_FILE_SIZE environment variable (default: 50mb) limits the size of uploaded import files and schema snapshots. Previously, imports were effectively unrestricted, allowing files larger than 50mb to be processed. With this change, imports exceeding the configured limit will be rejected. Increase IMPORT_MAX_FILE_SIZE to restore the previous behavior.
Updated background query flag handling for POST /utils/import/:collection
The background query flag now treats a valueless indicator (i.e. ?background) as true. If you previously relied on a valueless background flag being interpreted as false, pass an explicit value instead (i.e. ?background=false).
Added a mode parameter and partial snapshot support to the schema diff endpoint (#27984)
The SDK schemaDiff command now takes its options as an object (schemaDiff(snapshot, { force, mode }))
Added support for restricting image transformation output size via ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (#27995)
Image transformation output is now restricted
Image transformations that project an output larger than ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (default 3000 px) on either axis are now rejected with an IllegalAssetTransformationError.
Replaced the TinyMCE editor powering the WYSIWYG with Tiptap (#27754 by @alvarosabu)
To avoid data loss, the editor preserves attributes (class, id, title, role, lang, dir, data-*, aria-*) and non-schema semantic tags. If stored HTML still contains markup the editor would normalize, the field is locked read-only with a warning dialog, so no edit or autosave can rewrite it before you confirm; raw-value editing is disabled while locked so the warning can't be bypassed.
ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (#27995 by @br41nslug)mode parameter and partial snapshot support to the schema diff endpoint (#27984 by @ComfortablyCoding)includeCollections/excludeCollections parameters (#27984 by @ComfortablyCoding)mode parameter and partial snapshot support to the schema diff endpoint (#27984 by @ComfortablyCoding)includeCollections/excludeCollections parameters (#27984 by @ComfortablyCoding)ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION (#27995 by @br41nslug)includeCollections/excludeCollections parameters (#27984 by @ComfortablyCoding)includeCollections/excludeCollections parameters (#27984 by @ComfortablyCoding)mode parameter and partial snapshot support to the schema diff endpoint (#27984 by @ComfortablyCoding)required and/or readonly to be set (#27688 by @sourav-18)delete permission on directus_versions (#27892 by @alex-hsieh)Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)
Added global setting for default save action (#27993 by @robluton)
Fixed OpenAPI spec error schema to match API error format (#27885 by @kheiner)
Restricted license key previews to administrators after initial project setup (#27886 by @ComfortablyCoding)
Stopped logging the missing custom IP header warning on /server/ping and /server/info, which are commonly hit directly (health checks) (#27903 by @dstockton)
Updated axios, sharp, liquidjs, js-yaml, minimatch, adm-zip, brace-expansion, linkify-it, fast-xml-parser and tar to address CVEs (#27990 by @br41nslug)
Fixed parsing of the deep query parameter, GraphQL nested arguments, and CSV import headers so keys dont collide with built-in object property names (#27992 by @br41nslug)
Fixed schema apply ignoring configured license (#27869 by @ComfortablyCoding)
Fixed aliased relational fields returning null in GraphQL when nested inside a Many-to-Any field (#27864 by @apoorva-01)
Fixed IP denylist not enforced for AI chat file downloads (#27994 by @br41nslug)
Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)
Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.
Fixed requests referencing duplicate primary keys resulting in forbidden error (#27882 by @lazerg)
Fixed manual flows triggerable by non authenticated users (#27997 by @br41nslug)
Fixed count, countAll, and PK counts being inflated when filtering across relations (#27926 by @ComfortablyCoding)
Fixed TUS uploads not respecting FILES_MIME_TYPE_ALLOW_LIST (#27793 by @amitmishra11)
Fixed WebSocket handlers not validating query parameters (#27845 by @tsushanth)
Fixed unnecessary schema cache rebuilds on permission-related changes (#27876 by @dstockton)
filter: { o2m: { id: { _eq: 5 } } }) is now type-checked instead of silently accepting any value (#27815 by @MahinAnowar)timestamp from directus_operations (#27942 by @kheiner)Updated the remaining *.io references to the current *.com domains where possible (#27948 by @kheiner)
Fixed OpenAPI spec error schema to match API error format (#27885 by @kheiner)
Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)
Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.
Added missing /users registration and 2FA endpoint openapi specs (#27857 by @kheiner)
Removed OpenAPI query parameters that the underlying controllers never honor (#27922 by @kheiner)
Added missing id path parameter to the /comments/{id} OpenAPI spec (#27884 by @kheiner)
Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)
Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.
Fixed background imports (POST /utils/import/:collection?background=true) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. (#27862 by @dstockton)
Added an IMPORT_MAX_FILE_SIZE environment variable that caps the size of an uploaded import file, returning 413 Content Too Large when exceeded. Unset (unlimited) by default.
@directus/app@17.0.0@directus/api@38.0.0@directus/composables@11.6.0@directus/constants@14.4.1create-directus-extension@12.1.2@directus/env@6.2.0@directus/errors@2.5.0@directus/extensions@4.0.2@directus/extensions-registry@4.0.2@directus/extensions-sdk@18.0.2@directus/memory@4.0.2@directus/pressure@4.0.2@directus/schema@14.0.1@directus/schema-builder@1.0.1@directus/specs@15.1.0@directus/storage-driver-azure@13.0.2@directus/storage-driver-cloudinary@13.0.2@directus/storage-driver-gcs@13.0.2@directus/storage-driver-s3@13.0.2@directus/storage-driver-supabase@4.0.2@directus/system-data@4.6.0@directus/themes@2.0.2@directus/types@16.1.0@directus/utils@13.5.2@directus/validation@3.0.2@directus/sdk@24.0.0
Today, we'd like to give you a glimpse of our work on the Soul of Anatolia DLC for Euro Truck Simulator 2 by showcasing some of the new assets we've been creating to make this map expansion unique!
Because the DLC is still very much a work in progress, it's not quite the right time to start previewing specific locations, as our map designers are still bringing them to life. Instead, we'd like to share a selection of the 3D models that our assets team has been hard at work creating, displayed in a placeholder setting for now.
Keep in mind that the assets we're showcasing today are just a glimpse of what's still to come. The assets team continues making new models throughout the entire development process, so what you're seeing here represents only a fraction of what will eventually make its way into the final product.
Based on our research team and close collaboration between our map and assets teams, these models are created to reflect the architecture and character of the region. In this map expansion, you will encounter plenty of different cities, each with its own unique architecture, so we need to capture a wide spectrum of buildings, from the big and small, modern and older city buildings to rural houses you would see when visiting the western part of Türkiye in real life.
Over time, they are being integrated into the map by the team working on this DLC, helping shape its towns, cities, and other locations across the map expansion. In total, we plan to create around 300 new generic assets, similar to the ones you see here, as well as our usual landmark assets, which are created for more significant buildings to make them instantly recognizable. You can look forward to seeing these in future blog posts.
If you are excited to be cruising in this map expansion, don't forget to support us by adding the Soul of Anatolia DLC to your Steam wishlist.
Also, remember to give our X/Twitter, Instagram, Facebook, Bluesky, and TikTok a follow, as you'll receive updates from our games straight to your feed. Or subscribe to our newsletter to stay informed. Until next time, we wish you safe travels!
Below are development builds for testing purposes.
Latest development build: 2.7.4.34 (July 29th 2026)
Latest stable release build: 2.7.4
https://github.com/clsid2/mpc-hc/releases/tag/2.7.4
This is a security release to address a range of vulnerabilities:
Upgrading is generally advised, but more so for instances using OIDC, SAML2 or LDAP authentication.
Thanks to Tanner Marks (GitHub), Gurmandeep Deol (LinkedIn) and whale120 (Blog, X, Working with DEVCORE Internship Program) for responsibly reporting issues addressed in this release.
The Extended Stable channel has been updated to 150.0.7871.212 for Windows and Mac which will roll out over the coming days/weeks.
Sound the alarm, because Works with Home Assistant just welcomed our newest partner to the program: FireAvert! 🎉 Specialists in fire safety, FireAvert are on a mission to keep you and your home out of harm’s way. They bring the very first gas and electric appliance shutoff devices to the program, and with them, a whole lot of peace of mind.
As ex-firefighter Peter Thorpe knows too well, a moment of forgetfulness is all it takes for a kitchen to end up in flames. And after close to twenty years of service witnessing the same devastating scenario repeat itself, he knew something had to be done. So he founded FireAvert, launching with the Auto Stove Shutoff for electric stovetops.
The device was already gaining momentum before FireAvert’s pitch caught the attention of Shark Tank, and for good reason. They say there’s no smoke without fire, but years on the job taught Thorpe that in the kitchen, that isn’t always the case. Smoke can build well before a flame takes hold – and that’s the window FireAvert’s shutoff works in. By listening for your standard smoke alarm, the device automatically shuts off your stove when the alarm sounds – cutting the heat at the source before a fire can catch.
“Excited to see FireAvert join the Home Assistant community. Smart homes shouldn’t just be convenient – they should help keep families safer too. This is exactly the kind of innovation the ecosystem needs.”
- Chasen Tolbert, FireAvertSince their launch, FireAvert’s range has expanded to include gas stove and small appliance shutoffs (think microwaves, air fryers, hot plates), so whatever’s most likely to be left on in your kitchen, there’s a shutoff for it. And with Z-Wave units now among them, it’s easier than ever to bring that protection straight into your Home Assistant setup.
The FireAvert shutoffs joining the program run on Z-Wave. For anyone unfamiliar, here’s a quick rundown: Z-Wave is an open smart home protocol that allows your devices to talk to each other regardless of the brand, without locking you into one ecosystem. It’s also a mesh network, where each device relays signals for the others to extend coverage across your home, reinforcing your connection.
While Z-Wave wasn’t a part of FireAvert’s initial product line, since then we’ve been pleased to see the company prioritize local control by producing shutoff devices with the open standard, and certifying them with the Z-Wave Alliance. We first met the FireAvert team at a San Diego alliance meeting back in 2025, and it was clear from the get-go that we were on the same wavelength: driven to build open, interoperable smart home tech that doesn’t require a cloud to keep your home protected.
FireAvert automatic shutoffs for electric and gas stoves
It’s important to note that FireAvert’s shutoffs don’t rely purely on Z-Wave to do their job, and they’ll keep protecting your kitchen even if your network drops out entirely. That kind of safety net is reassuring for anyone, but even more so for those with caring responsibilities or aging relatives to worry about.
Likewise, FireAvert’s shutoffs don’t depend on a battery to function: just plug your stove or small appliance into the shutoff device, and the device into your wall socket – and you’re all set. As long as your appliance has power, the shutoff is on duty. And FireAvert back up that dependability where it counts: all four devices come with a lifetime warranty, and are independently tested to CSA and UL standards – confirming the hardware meets strict, recognized electrical safety requirements.
Just like every device certified by the Works with Home Assistant program, FireAvert’s shutoffs have also been rigorously tested by our in-house team to ensure they are up to code with our core requirements of local control and privacy.
Check out the devices that made the grade:
But it’s not just about adding devices to a list – our community is the engine of everything we do, and by joining it FireAvert commits to providing long-term support to make certain their devices continue to work smoothly within your setup.
While there are already certified water shutoff devices in the program, stove shutoffs are a first, bringing a brand-new category of safety tech to Home Assistant users. It’s exactly the kind of innovation we love to see: more ways for our community to manage their smart homes, on their own terms.
That expansion is core to what the Open Home Foundation – which operates the Works with Home Assistant program – is about: keeping smart homes local, private, and safe. If you’d like to see more safety-focused partners like FireAvert join the program, consider subscribing to Home Assistant Cloud or buying official hardware like the Home Assistant Connect ZWA-2. Every bit of support helps us expand and maintain the program for all ⚒️.
Forged to protect the community, FireAvert are a natural match for ours. We’re thrilled to have them join the ranks, and excited for Home Assistant users to be able to add another line of defense for their smart homes, and the people and pets who live in them. Head to our certified device list to discover the full range of devices to safeguard your home.
Q: If I have a device that is not listed under Works with Home Assistant does this mean it’s not supported?
A: No! It just means that it hasn’t gone through a testing schedule with our team or doesn’t fit the requirements of the program. It might function perfectly well but be added to the testing schedule later down the road, or it might work under a different connectivity type that we don’t currently test under the program.
Q: OK, so what’s the point of the Works with program?
A: It highlights the devices we know work well with Home Assistant and the brands that make a long-term commitment to keeping support for these devices going. The certification agreement specifies that the devices must have the functionality you would expect within Home Assistant, operate locally without the need for the cloud, and that they will continue to do so long term.
Q: How were these devices tested?
A: All devices in this list were tested using a standard Home Assistant Green Hub with the Home Assistant Connect ZWA-2 as the Z-Wave adapter and with our Z-Wave integration. If you have another hub/adapter/integration that’s not a problem but we test against these as they are the most effective way for our team to certify within our ecosystem.
Q: Will you be adding more FireAvert devices to the program?
A: Why not! We’re thrilled to foster a close relationship with the team at FireAvert to work together on any upcoming releases or add in further products that are not yet listed here.
Addressed a startup crash on Windows that could occur after updating Firefox, when some of the application's internal files could not be loaded. Firefox should now start in these cases, although parts of the interface may not display correctly until a further update completes (Bug 2056926).
Fixed audio playing silently on some music and audio streaming sites after pausing and resuming playback (Bug 2053586).
Fixed the New Tab page background flashing a few seconds after the page loaded when a custom wallpaper was in use (Bug 2056650).
Fixed a crash that could occur when a page loaded a frame using a javascript: address (Bug 2054485).
Fixed a crash that could occur while typing text in an editable area of a page (Bug 2053867).
Fixed a search engine you had already installed yourself being labeled as "New" when Firefox later started offering the same engine (Bug 2053710).
Improved pointer lock, used by games and other immersive web content, so that the mouse pointer is less likely to escape the Firefox window (Bug 1255338, Bug 2040628).
Fixed an issue in the Inspector's Rules view where pseudo-elements could only be expanded once per selected element (Bug 2054525).
Fixed View Page Source failing to load blob: documents (Bug 2054428).
Fixed View Page Source timing out on documents that inherit their origin, such as frames using the srcdoc attribute (Bug 2054487).
Reference link to 153.0 release notes.
Some Windows users may experience a crash on startup after updating, caused by an incomplete update leaving the Firefox installation in an inconsistent state (Bug 1681745). If you are affected, downloading Firefox from firefox.com and installing it over your existing installation will repair it. Your bookmarks, passwords and other data are stored separately and will not be affected.


VIENNA, Austria – July 28, 2026 – Enterprise software provider Proxmox Server Solutions today announced a collaboration with NVIDIA to enhance the infrastructure layer of the modern AI-factory. By integrating the proven reliability of Proxmox Virtual Environment (Proxmox VE) with NVIDIA Mission Control™, enterprises can deploy a highly resilient, virtualized management plane designed to power the world’s most advanced AI workloads running on NVIDIA accelerated infrastructure, including the NVIDIA Blackwell and NVIDIA Vera Rubin platforms.
As generative AI moves into large-scale production, the AI factory requires a seamless transition from raw hardware to orchestrated, consumable resources. NVIDIA Mission Control streamlines this entire lifecycle, from developer workload scheduling and orchestration to autonomous recovery. Proxmox VE serves as the critical virtualization layer beneath this ecosystem, providing the stable, highly available substrate for hosting the management services that drive NVIDIA Mission Control’s intelligence.
A key pillar of this collaboration is the optimization of Proxmox VE for NVIDIA’s frontier silicon. Proxmox VE is being engineered specifically to support the bring-up of NVIDIA Grace and NVIDIA Vera CPU architectures, ensuring seamless deployment of advanced hardware in the modern AI data center.
The synergy between Proxmox VE and NVIDIA Mission Control creates an “always-on” environment for AI innovation. While NVIDIA Mission Control provides the advanced management intelligence for the AI-factory, Proxmox VE delivers the underlying, mission-critical resilience. Through native clustering and live-migration capabilities, Proxmox VE ensures that the software services governing the AI-factory remain operational and scalable, maximizing the total ROI of the entire NVIDIA-powered AI-factory.
"Proxmox VE delivers proven, mission-critical reliability for the most demanding workloads- whether in AI-factory pipelines, regulated industries, sovereign clouds, " said Tim Marx, COO of Proxmox. "By joining the NVIDIA Mission Control ecosystem, we are offering enterprises the structural reliability needed to run, protect, and scale their most valuable AI workloads, working alongside one of the industry’s most essential partner for the AI era."
###
About Proxmox Server Solutions
Proxmox Server Solutions provides powerful, intuitive open-source server software that guarantees vendor independence and minimizes total cost of ownership. Enterprises of all sizes rely on the company’s reliable vendor support, certified training services, and a global network of 3,000 integration partners to ensure business continuity. Established in 2005 and headquartered in Vienna, Austria, tens of thousands of corporate customers worldwide trust Proxmox solutions to secure their mission-critical IT environments.
Contact: Daniela Häsler, Proxmox Server Solutions GmbH
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2026-07-27)
the FTP-server (default-disabled) would allow uploading to any folder that the copyparty process had permission to write to, but with certain limitations; see GHSA-phv8-wgjp-g4p9
th-covers: no (volflag or global) 856fadaxbr / xar did not include old/new abspath as parameters; now they do c122e10xiu crashed if the fork-flag was set (thx @stackxp!) aa86235xau without json-flag would be given the wark (file hash) instead of the abspath bae77b9?v) inside shares 6a9437bxbu hooks 9912a95ffmpeg-headless instead of ffmpeg-full (thx @nyakase!) fface52| download link | is it good? | description |
|---|---|---|
| copyparty-sfx.py | ✅ the best 👍 | runs anywhere! only needs python |
| copyparty-en.py | ✅ also good | same but english-only, no i18n |
| a docker image | it's ok | good if you prefer docker 🐋 |
| copyparty.exe | ⚠️ acceptable | for win8 or later; built-in thumbnailer |
| u2c.exe | ⚠️ acceptable | CLI uploader as a win7+ exe (video) |
| copyparty.pyz | ⚠️ acceptable | similar to the regular sfx, mostly worse |
| copyparty-en.pyz | ⚠️ acceptable | english-only, no smb-server |
| copyparty32.exe | ⛔️ dangerous | for win7 -- never expose to the internet! |
| cpp-winpe64.exe | ⛔️ dangerous | runs on 64bit WinPE, otherwise useless |
| bootable usb | ┐(゚∀゚)┌ | a surprisingly useful joke (x86_64) |
Warning
After upgrade, you need to run php bin/console doctrine:migrations:migrate (or equivalent) as webserver user after upgrade.. If you are running a docker container, use sudo docker exec --user=www-data partdb php bin/console doctrine:migrations:migrate, or sudo -E inside the docker container, to ensure that the migrations are applied to the correct database.
Important
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
Full Changelog: v2.13.4...v2.14.0
Docker images have been built and pushed:
Docker Hub:
alexta69/metube:latestalexta69/metube:2026.07.27GitHub Container Registry:
ghcr.io/alexta69/metube:latestghcr.io/alexta69/metube:2026.07.27