{"id":11293,"date":"2026-03-12T10:03:50","date_gmt":"2026-03-12T10:03:50","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/12\/chrome-security-update-patch-for-29-vulnerabilities-that-allow-remote-code-execution\/"},"modified":"2026-03-12T10:03:50","modified_gmt":"2026-03-12T10:03:50","slug":"chrome-security-update-patch-for-29-vulnerabilities-that-allow-remote-code-execution","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/12\/chrome-security-update-patch-for-29-vulnerabilities-that-allow-remote-code-execution\/","title":{"rendered":"Chrome Security Update \u2013 Patch for 29 Vulnerabilities that Allow Remote Code Execution"},"content":{"rendered":"<p>    Chrome Security Update \u2013 Patch for 29 Vulnerabilities that Allow Remote Code Execution<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has officially released Chrome version 146 to the stable channel, delivering crucial <a href=\"https:\/\/cybersecuritynews.com\/chrome-security-update-patch-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">security updates for Windows, Mac, and Linux users.<\/a><\/p>\n<p>Rolling out over the coming days, Chrome 146.0.7680.71 for Linux and 146.0.7680.71\/72 for Windows and Mac addresses 29 security vulnerabilities.<\/p>\n<p>Many of these flaws, if left unpatched, could allow remote attackers to execute arbitrary code, compromise system integrity, or trigger denial-of-service conditions.<\/p>\n<p>The most severe vulnerability resolved in this release is CVE-2026-3913, a Critical-severity heap buffer overflow in the WebML component.<\/p>\n<p>Discovered by security researcher Tobias Wienand, this memory corruption issue earned a $33,000 bug bounty. A <a href=\"https:\/\/cybersecuritynews.com\/windows-heap-based-buffer-overflow-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">heap buffer overflow <\/a>occurs when a program writes more data to a memory location than the allocated size allows.<\/p>\n<p>Threat actors can exploit this weakness to overwrite adjacent memory structures, potentially leading to remote code execution (RCE) when a user simply visits a maliciously crafted web page.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-high-severity-vulnerabilities-patched\"><strong>High-Severity Vulnerabilities Patched<\/strong><\/h2>\n<p>In addition to the critical flaw, Google patched 11 High-severity vulnerabilities. The WebML API proved to be a frequent target in this update cycle, with two additional High-severity bugs (CVE-2026-3914 and CVE-2026-3915) earning $43,000 each in bounty payouts.<\/p>\n<p>Other significant <a href=\"https:\/\/cybersecuritynews.com\/linux-kernel-out-of-bounds-write-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">High-severity patches include out-of-bounds read<\/a> and use-after-free (UAF) vulnerabilities across various browser components.<\/p>\n<p>UAF flaws occur when a program attempts to access memory that has been freed, a technique attackers frequently use to <a href=\"https:\/\/cybersecuritynews.com\/styx-stealer-data-theft\/\" target=\"_blank\" rel=\"noreferrer noopener\">bypass browser security sandboxes.<\/a><\/p>\n<p>Key High-severity fixes include:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>CVE-2026-3916:<\/strong> An out-of-bounds read flaw in the Web Speech component.<\/li>\n<li>\n<strong>CVE-2026-3917 &amp; CVE-2026-3918:<\/strong> <a href=\"https:\/\/cybersecuritynews.com\/chrome-uaf-vulnerabilities-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">Use-after-free vulnerabilities<\/a> in the Agents and WebMCP components.<\/li>\n<li>\n<strong>CVE-2026-3919:<\/strong> A use-after-free bug in Chrome Extensions.<\/li>\n<li>\n<strong>CVE-2026-3921 to CVE-2026-3924:<\/strong> Multiple use-after-free bugs affecting TextEncoding, MediaStream, WebMIDI, and WindowDialog.<\/li>\n<\/ul>\n<p>The update also resolves multiple Medium and Low-severity issues. These range from incorrect security UI implementations in components like PictureInPicture to insufficient policy enforcement in PDF and DevTools.<\/p>\n<p>Google paid out well over $150,000 in combined bug bounties to independent researchers for identifying these issues before they could be actively exploited.<\/p>\n<p>To protect users, <a href=\"http:\/\/omereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop_10.html\" id=\"omereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop_10.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google restricts access to specific bug details<\/a> and exploit links until a majority of the user base has updated their browsers.<\/p>\n<p>This prevents threat actors from <a href=\"https:\/\/cybersecuritynews.com\/chrome-emergency-security-update\/\" target=\"_blank\" rel=\"noreferrer noopener\">reverse-engineering the patches to target vulnerable individuals<\/a>. As attackers increasingly target web browsers, individuals and organizations must prioritize timely security updates to protect against sophisticated threats.<\/p>\n<p>To ensure your browser is protected, open Google Chrome, navigate to the three-dot menu, select \u201cHelp,\u201d and click on \u201cAbout Google Chrome.\u201d<\/p>\n<p>The browser will automatically check for the version 146 update and install it. A quick browser restart is required to apply the latest protections, reinforcing your <a href=\"https:\/\/cybersecuritynews.com\/n8n-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">defense-in-depth strategy <\/a>against emerging vulnerabilities.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chrome-security-update-29-vulnerabilities\/\">Chrome Security Update \u2013 Patch for 29 Vulnerabilities that Allow Remote Code Execution<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chrome-security-update-29-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chrome Security Update \u2013 Patch for 29 Vulnerabilities that Allow Remote Code Execution Google has officially released Chrome version 146 to the stable channel, delivering crucial security updates for Windows, Mac, and Linux users. Rolling out over the coming days, Chrome 146.0.7680.71 for Linux and 146.0.7680.71\/72 for Windows and Mac addresses 29 security vulnerabilities. Many [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[768,129,63,2178],"tags":[130],"class_list":["post-11293","post","type-post","status-publish","format-standard","hentry","category-chrome","category-cyber-security","category-cyber-security-news","category-security-updates","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11293"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11293"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11293\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11293"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11293"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11293"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}