{"id":12891,"date":"2026-05-15T10:04:02","date_gmt":"2026-05-15T10:04:02","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/15\/79-chrome-vulnerabilities-patched-including-14-critical-ones-update-now\/"},"modified":"2026-05-15T10:04:02","modified_gmt":"2026-05-15T10:04:02","slug":"79-chrome-vulnerabilities-patched-including-14-critical-ones-update-now","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/15\/79-chrome-vulnerabilities-patched-including-14-critical-ones-update-now\/","title":{"rendered":"79 Chrome Vulnerabilities Patched, Including 14 Critical One\u2019s \u2013 Update Now!"},"content":{"rendered":"<p>    79 Chrome Vulnerabilities Patched, Including 14 Critical One\u2019s \u2013 Update Now!<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has rolled out a massive <a href=\"https:\/\/cybersecuritynews.com\/chrome-security-update-29-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">security update for its Chrome browser<\/a>, sealing a staggering 79 vulnerabilities before threat actors can exploit them.<\/p>\n<p>With 14 of these flaws rated as critical, browsing the web on an outdated version leaves your entire system wide open to devastating cyberattacks.<\/p>\n<p>The newest stable release bumps Chrome to 148.0.7778.167\/168 on Windows and Mac, while Linux users will upgrade to 148.0.7778.167.<\/p>\n<p>Google is deploying this patch over the coming days, but proactive users and enterprise administrators should trigger the update manually.<\/p>\n<p>The sheer volume of this release highlights the constant battle against memory corruption bugs, particularly \u201cUse-after-free\u201d (UAF) and \u201cHeap buffer overflow\u201d flaws that commonly plague complex browser architectures.<\/p>\n<p>As standard practice, <a href=\"https:\/\/cybersecuritynews.com\/google-chrome-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google keeps specific exploit details<\/a> and proof-of-concept code restricted.<\/p>\n<p>This creates a vital window for the global user base to install the patch before malware operators weaponize the disclosures.<\/p>\n<p>However, the tech giant has already paid out hefty <a href=\"https:\/\/cybersecuritynews.com\/googles-bug-bounty-program-high-reward\/\" target=\"_blank\" rel=\"noreferrer noopener\">bug bounties<\/a> to independent researchers, highlighting the severity of the findings.<\/p>\n<p>The highest reward of $43,000 went to an external researcher who discovered a critical heap buffer overflow in the WebML component.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-critical-chrome-vulnerabilities-patched\"><strong>Critical Chrome Vulnerabilities Patched<\/strong><\/h2>\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/05\/stable-channel-update-for-desktop_12.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google released fixes for multiple memory management flaws<\/a> that could let attackers execute arbitrary code through malicious HTML pages.<\/p>\n<p>Below is a breakdown of the most severe vulnerabilities patched in this update that every security intelligence team needs to track.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE ID<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Component<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Vulnerability Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Reporter<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Bounty<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8509<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">WebML<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Heap buffer overflow<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">c6eed09fc8b174b0f3eebedcceb1e792<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">$43,000<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2026-8510<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Skia<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Integer overflow<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">q@calif.io<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">$25,000<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8511<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">UI<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8512<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">FileSystem<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8513<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Input<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8514<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Aura<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8515<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">HID<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8516<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">DataTransfer<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Insufficient validation of untrusted input<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8517<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">WebShare<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Object lifecycle issue<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8518<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Blink<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8519<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">ANGLE<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Integer overflow<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8520<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Payments<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Race condition<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8521<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Tab Groups<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-8522<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Downloads<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Threat actors heavily target browser <a href=\"https:\/\/cybersecuritynews.com\/aws-bedrock-agentcore-sandbox-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerabilities to bypass sandboxes<\/a>, steal sensitive data, and compromise the underlying operating system.<\/p>\n<p>Delaying this patch is a direct risk to your infrastructure. Take these immediate steps to secure your environment:<\/p>\n<ul class=\"wp-block-list\">\n<li>Navigate to the three-dot menu in the top right corner of your Chrome browser.<\/li>\n<li>Select Help, then click on About Google Chrome.<\/li>\n<li>Allow the browser to fetch and install version 148 automatically.<\/li>\n<li>Click Relaunch to apply the security fixes and clear active sessions.<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/79-chrome-vulnerabilities-patched\/\">79 Chrome Vulnerabilities Patched, Including 14 Critical One\u2019s \u2013 Update Now!<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/79-chrome-vulnerabilities-patched\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>79 Chrome Vulnerabilities Patched, Including 14 Critical One\u2019s \u2013 Update Now! Google has rolled out a massive security update for its Chrome browser, sealing a staggering 79 vulnerabilities before threat actors can exploit them. With 14 of these flaws rated as critical, browsing the web on an outdated version leaves your entire system wide open [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,163,648],"tags":[130],"class_list":["post-12891","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-google","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12891"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12891"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12891\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}