{"id":13234,"date":"2026-05-29T10:03:36","date_gmt":"2026-05-29T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/29\/google-patches-151-vulnerabilities-in-chrome-including-22-critical-ones\/"},"modified":"2026-05-29T10:03:36","modified_gmt":"2026-05-29T10:03:36","slug":"google-patches-151-vulnerabilities-in-chrome-including-22-critical-ones","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/29\/google-patches-151-vulnerabilities-in-chrome-including-22-critical-ones\/","title":{"rendered":"Google Patches 151 Vulnerabilities in Chrome, Including 22 Critical Ones"},"content":{"rendered":"<p>    Google Patches 151 Vulnerabilities in Chrome, Including 22 Critical Ones<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Google has pushed a major <a href=\"https:\/\/cybersecuritynews.com\/chrome148-vulnerabilities-patched\/\" target=\"_blank\" rel=\"noreferrer noopener\">Chrome Stable update<\/a> that fixes 151 security flaws, including 22 critical vulnerabilities affecting core graphics, networking, media, and UI components across Windows, macOS, and Linux.<\/p>\n<p class=\"wp-block-paragraph\">The Stable channel has been updated to version 148.0.7778.216\/217 for Windows, 148.0.7778.215\/216 for macOS, and 148.0.7778.215 for Linux, with the rollout scheduled over the coming days and weeks.<\/p>\n<p class=\"wp-block-paragraph\">A full list of code changes between builds 148.0.7778.180 and 148.0.7778.217 is available in the Chromium source log. However, Google is restricting detailed bug information until most users receive the patch.<\/p>\n<p class=\"wp-block-paragraph\">This staggered disclosure reduces the risk that attackers will weaponize the bugs against unpatched systems.<\/p>\n<p class=\"wp-block-paragraph\">Google credits both internal teams and external security researchers for surfacing the issues during the development cycle and notes that many bugs were caught before they ever reached the stable branch.<\/p>\n<p class=\"wp-block-paragraph\">The company again highlights its use of sanitizers, fuzzers, and control-flow integrity to detect memory corruption and undefined behavior at scale.<\/p>\n<h2 id=\"h-151-vulnerabilities-patched-in-chrome\" class=\"wp-block-heading\"><strong>151 Vulnerabilities Patched in Chrome<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Of the 151 vulnerabilities, 22 are rated critical, and several have already attracted substantial bug bounties.<\/p>\n<p class=\"wp-block-paragraph\">Notable externally reported issues include an out-of-bounds write in the GPU process (CVE-2026-9872), use-after-free in Network (CVE-2026-9873), a use-after-free in Dawn (CVE-2026-9874), and an out-of-bounds read in WebGL (CVE-2026-9875), with rewards of up to 43,000 USD per report.<\/p>\n<p class=\"wp-block-paragraph\">These flaws could enable sandbox escapes, remote code execution, or data corruption if an attacker can lure a victim to a malicious page.<\/p>\n<p class=\"wp-block-paragraph\">The majority of critical fixes, however, come from Google\u2019s own teams and target the <a href=\"https:\/\/cybersecuritynews.com\/critical-windows-graphics-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">graphics and rendering stack<\/a>, including ANGLE, Skia, WebGL, Dawn, XR, Bluetooth, UI, and core browser infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">Issues range from use\u2011after\u2011free and heap buffer overflows to integer overflows and insufficient validation of untrusted input, all of which are classic building blocks for reliable exploits in modern browsers.<\/p>\n<p class=\"wp-block-paragraph\">Beyond the critical bugs, <a href=\"https:\/\/cybersecuritynews.com\/google-chrome-emergency-security-update\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google patched <\/a>a large set of high\u2011severity flaws across DOM, Accessibility, Site Isolation, WebCodecs, PDF\/PDFium, WebRTC, Passwords, WebAppInstalls, Media, USB, and more.<\/p>\n<p class=\"wp-block-paragraph\">These include additional use\u2011after\u2011free conditions, <a href=\"https:\/\/cybersecuritynews.com\/out-of-bounds-read-and-write\/\" target=\"_blank\" rel=\"noreferrer noopener\">out\u2011of\u2011bounds reads and writes<\/a>, race conditions, and uninitialized memory use, many of which were reported internally. However, some also credited researchers at Mozilla, Microsoft, OpenAI, and others.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE ID<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Component<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Bug type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Reporter<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Reward<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9872<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">GPU<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Out of bounds write<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">cinzinga<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">43,000 USD<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9873<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Network<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">cinzinga<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">43,000 USD<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9874<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Dawn<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Anonymous<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">11,000 USD<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9875<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">WebGL<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Out of bounds read<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Anonymous<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">5,000 USD<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9876<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">WebGL<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">happy2me<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TBD<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9877<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">ANGLE<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9878<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">ANGLE<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9879<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">ANGLE<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Out of bounds write<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9880<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">WebGL<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Insufficient validation of untrusted input<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9881<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Bluetooth<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9882<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">ANGLE<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Integer overflow<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9883<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Base<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9884<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Browser<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9885<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">UI<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Insufficient validation of untrusted input<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9886<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Base<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9887<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Proxy<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9888<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">WebView<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9889<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Dawn<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Out of bounds read and write<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9890<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">XR<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9891<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Extensions<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9892<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Skia<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Inappropriate implementation<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-9893<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Skia<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use after free<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Google<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Medium\u2011severity vulnerabilities cover further integer overflows and insufficient input validation in components such as <a href=\"https:\/\/cybersecuritynews.com\/chrome148-vulnerabilities-patched\/\" target=\"_blank\" rel=\"noreferrer noopener\">ANGLE, Skia, USB, V8, and Headless<\/a>, with smaller but still significant bounties paid out.<\/p>\n<p class=\"wp-block-paragraph\">Google notes that many of these bugs were found using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL, reinforcing the role of automated testing in reducing browser attack surface.<\/p>\n<p class=\"wp-block-paragraph\">As usual, some bug details will remain private if they also affect widely used third\u2011party libraries that have not yet shipped their own fixes.<\/p>\n<p class=\"wp-block-paragraph\">Enterprise defenders and end users are urged to <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/05\/stable-channel-update-for-desktop_0877304591.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">upgrade Chrome to the latest 148.0.7778.x<\/a> Stable build as soon as it becomes available for their platform, or to switch to a faster release channel if they need earlier access to patches.<\/p>\n<p class=\"wp-block-paragraph\">Google encourages anyone who discovers new issues to file them via the public bug tracker and to use the Chrome community help forum for support on update and deployment issues.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/151-chrome-vulnerabilities-patched\/\">Google Patches 151 Vulnerabilities in Chrome, Including 22 Critical Ones<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/151-chrome-vulnerabilities-patched\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Patches 151 Vulnerabilities in Chrome, Including 22 Critical Ones Google has pushed a major Chrome Stable update that fixes 151 security flaws, including 22 critical vulnerabilities affecting core graphics, networking, media, and UI components across Windows, macOS, and Linux. The Stable channel has been updated to version 148.0.7778.216\/217 for Windows, 148.0.7778.215\/216 for macOS, and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[768,129,63,648],"tags":[130],"class_list":["post-13234","post","type-post","status-publish","format-standard","hentry","category-chrome","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13234"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13234"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13234\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}