#chrome
8 articles
The technology sector remains the primary focus of Chrome-related vulnerabilities, with eight articles published between April and July 2026 covering five high-severity and three critical issues. Key CVEs include CVE-2026-8550 and CVE-2026-8556, both rated 6.5, alongside CVE-2026-8541 and CVE-2026-8543 at 5.3, and CVE-2026-8566 at 3.0. These vulnerabilities affect users across global consumer and mobile markets, underscoring the browser’s widespread exposure.
HIGHBrowser-Only Ransomware Exploits Chrome File System API via
Check Point Research found a DeepSeek-generated sample using Chrome's File System Access API to encrypt Android photo directories — no native payload or exploit required.
HIGHChrome 148.0.7778.168 Patches Two High-Severity OOB Read Flaws
Google Chrome 148.0.7778.168 fixes CVE-2026-8543 and CVE-2026-8541 — two high-severity out-of-bounds read vulnerabilities in FileSystem and UI components on Mac and all platforms.
HIGHChrome 148 Patches AI Site Isolation Bypass, Android Payment Flaw
CVE-2026-8568 (CVSS 3.1) lets attackers bypass Chrome Site Isolation via AI features after renderer compromise; CVE-2026-8566 (CVSS 4.3) targets Android Payments.
HIGHChrome 148 Patches ANGLE Data Leak, Google Lens UAF
Google fixed CVE-2026-8556 (ANGLE cross-origin leak) and CVE-2026-8550 (Google Lens use-after-free) in Chrome 148.0.7778.168 for Windows. Both flaws require a compromised renderer.
CRITICALChrome 148 Patches 79 Flaws, 14 Critical Including Heap Overflow
Google's Chrome 148 update fixes 79 vulnerabilities, 14 critical — including heap buffer overflow CVE-2026-8509 ($43K bounty) and integer overflow CVE-2026-8510 in Skia ($25K...
CRITICALChrome 148 Patches 127 Flaws, Three Critical Use-After-Free Bugs
Google's Chrome 148 fixes 127 vulnerabilities including three critical-severity bugs (CVE-2026-7896, CVE-2026-7897, CVE-2026-7898) — integer overflow in Blink and use-after-free...
CRITICALChrome 147, Firefox 150 Patch Critical Code Execution Flaws
Google and Mozilla ship Chrome 147 and Firefox 150 to fix critical and high-severity vulnerabilities enabling arbitrary code execution. Users urged to update immediately.
HIGH108 Malicious Chrome Extensions Hijack Browsers, Steal Google and Telegram Data
Socket identified 108 malicious Chrome extensions that infected 20,000 users, stealing Google and Telegram session cookies and injecting ads via a shared command-and-control server.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.