#chrome
7 articles
The technology sector remains the primary target in a recent wave of exploits affecting Google Chrome, with a global impact. Over a period from April 19 to May 16, 2026, seven articles documented four high-severity and three critical-severity vulnerabilities. Key CVEs include CVE-2026-8550, CVE-2026-8556, CVE-2026-8541, CVE-2026-8543, and CVE-2026-8566, with scores ranging from 3 to 6.5. These flaws have drawn attention across all sectors and regions.
HIGHChrome 148.0.7778.168 Patches Two High-Severity OOB Read Flaws
Google Chrome 148.0.7778.168 fixes CVE-2026-8543 and CVE-2026-8541 — two high-severity out-of-bounds read vulnerabilities in FileSystem and UI components on Mac and all platforms.
HIGHChrome 148 Patches AI Site Isolation Bypass, Android Payment Flaw
CVE-2026-8568 (CVSS 3.1) lets attackers bypass Chrome Site Isolation via AI features after renderer compromise; CVE-2026-8566 (CVSS 4.3) targets Android Payments.
HIGHChrome 148 Patches ANGLE Data Leak, Google Lens UAF
Google fixed CVE-2026-8556 (ANGLE cross-origin leak) and CVE-2026-8550 (Google Lens use-after-free) in Chrome 148.0.7778.168 for Windows. Both flaws require a compromised renderer.
CRITICALChrome 148 Patches 79 Flaws, 14 Critical Including Heap Overflow
Google's Chrome 148 update fixes 79 vulnerabilities, 14 critical — including heap buffer overflow CVE-2026-8509 ($43K bounty) and integer overflow CVE-2026-8510 in Skia ($25K...
CRITICALChrome 148 Patches 127 Flaws, Three Critical Use-After-Free Bugs
Google's Chrome 148 fixes 127 vulnerabilities including three critical-severity bugs (CVE-2026-7896, CVE-2026-7897, CVE-2026-7898) — integer overflow in Blink and use-after-free...
CRITICALChrome 147, Firefox 150 Patch Critical Code Execution Flaws
Google and Mozilla ship Chrome 147 and Firefox 150 to fix critical and high-severity vulnerabilities enabling arbitrary code execution. Users urged to update immediately.
HIGH108 Malicious Chrome Extensions Hijack Browsers, Steal Google and Telegram Data
Socket identified 108 malicious Chrome extensions that infected 20,000 users, stealing Google and Telegram session cookies and injecting ads via a shared command-and-control server.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.