{"id":13564,"date":"2026-06-12T10:03:43","date_gmt":"2026-06-12T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/12\/google-patches-28-chrome-vulnerabilities-that-allow-attackers-to-execute-malicious-code\/"},"modified":"2026-06-12T10:03:43","modified_gmt":"2026-06-12T10:03:43","slug":"google-patches-28-chrome-vulnerabilities-that-allow-attackers-to-execute-malicious-code","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/12\/google-patches-28-chrome-vulnerabilities-that-allow-attackers-to-execute-malicious-code\/","title":{"rendered":"Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code"},"content":{"rendered":"<p>    Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Google has released a new <a href=\"https:\/\/cybersecuritynews.com\/chrome-security-updates\/\" target=\"_blank\" rel=\"noreferrer noopener\">Chrome security update<\/a> addressing 28 vulnerabilities, including several critical flaws that could allow attackers to execute malicious code on affected systems.<\/p>\n<p class=\"wp-block-paragraph\">The latest Stable channel update upgrades Chrome to version 149.0.7827.114\/.115 on Windows and macOS, and to 149.0.7827.114 on Linux.<\/p>\n<p class=\"wp-block-paragraph\">The rollout is being deployed gradually and is expected to reach users over the coming days and weeks. Google has also published a detailed changelog outlining all modifications included in this release.<\/p>\n<h2 id=\"h-critical-vulnerabilities-enable-code-execution\" class=\"wp-block-heading\"><strong>Critical Vulnerabilities Enable Code Execution<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Among the most serious issues patched are multiple critical memory-corruption vulnerabilities.<\/p>\n<p class=\"wp-block-paragraph\">These include several use-after-free flaws in core components, including Core, DigitalCredentials, and WebMIDI, identified as CVE-2026-12007, CVE-2026-12008, and CVE-2026-12011.<\/p>\n<p class=\"wp-block-paragraph\">Such vulnerabilities occur when memory is improperly managed, allowing attackers to manipulate freed memory regions.<\/p>\n<p class=\"wp-block-paragraph\">Google also addressed a critical heap buffer overflow vulnerability in the GPU component, tracked as CVE-2026-12010, along with an insufficient validation of untrusted input issue in the Accessibility component, identified as CVE-2026-12009.<\/p>\n<p class=\"wp-block-paragraph\">These flaws could be exploited by convincing users to visit specially crafted web pages, potentially enabling arbitrary code execution and leading to full system compromise.<\/p>\n<p class=\"wp-block-paragraph\">In addition to the critical vulnerabilities, the update resolves numerous high-severity issues affecting a wide range of Chrome components.<\/p>\n<p class=\"wp-block-paragraph\">Several of these involve use-after-free vulnerabilities across Network, Media, Autofill, GPU, Video, and Views modules. These bugs can lead to memory corruption and are often leveraged in exploit chains.<\/p>\n<p class=\"wp-block-paragraph\">Other high-severity issues include out-of-bounds read and write vulnerabilities in components such as <a href=\"https:\/\/cybersecuritynews.com\/dolby-codec-android-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Codecs<\/a>, Video, and VideoCapture, which could allow attackers to access or manipulate memory in unintended ways.<\/p>\n<p class=\"wp-block-paragraph\">A heap buffer overflow vulnerability in the GPU component further increases the risk of exploitation. The update also fixes multiple instances of insufficient validation of untrusted input in DevTools, Extensions, Network, and Linux Toolkit Theming.<\/p>\n<p class=\"wp-block-paragraph\">In addition, Google addressed improper policy enforcement issues in DevTools and Headless mode, as well as a <a href=\"https:\/\/cybersecuritynews.com\/cisa-linux-kernel-race-condition-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">race condition vulnerability<\/a> in Safe Browsing.<\/p>\n<p class=\"wp-block-paragraph\">These weaknesses could potentially be abused to bypass security restrictions or interfere with browser protections.<\/p>\n<p class=\"wp-block-paragraph\">Although Google has not confirmed whether these vulnerabilities are being <a href=\"https:\/\/cybersecuritynews.com\/google-chrome-0-day-vulnerability-exploited-in-the-wild-update-now\/\" target=\"_blank\" rel=\"noreferrer noopener\">actively exploited in the wild<\/a>, the presence of multiple memory-related flaws significantly raises the likelihood of exploitation.<\/p>\n<p class=\"wp-block-paragraph\">Attackers frequently target such vulnerabilities through malicious websites, exploit kits, or compromised advertising networks.<\/p>\n<p class=\"wp-block-paragraph\">To minimize risk, Google has restricted access to detailed vulnerability information until a majority of users have installed the update.<\/p>\n<p class=\"wp-block-paragraph\">This approach helps prevent attackers from analyzing patches to develop exploits before systems are secured. Google credited both internal security teams and external researchers for identifying and reporting these vulnerabilities.<\/p>\n<p class=\"wp-block-paragraph\">The company also emphasized the role of advanced detection tools such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL in discovering and mitigating security flaws during development.<\/p>\n<p class=\"wp-block-paragraph\">Users are strongly encouraged to <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/06\/stable-channel-update-for-desktop_01962725236.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">update Chrome immediately to the latest version<\/a> to protect against potential threats. While automatic updates are typically enabled, users can manually verify their browser version through the Chrome settings panel.<\/p>\n<p class=\"wp-block-paragraph\">Organizations should prioritize patch deployment across all systems to reduce exposure and prevent possible exploitation.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/28-chrome-vulnerabilities-patched\/\">Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/28-chrome-vulnerabilities-patched\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code Google has released a new Chrome security update addressing 28 vulnerabilities, including several critical flaws that could allow attackers to execute malicious code on affected systems. The latest Stable channel update upgrades Chrome to version 149.0.7827.114\/.115 on Windows and macOS, and to 149.0.7827.114 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-13564","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13564"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13564"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13564\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}