Monday, October 5, 2026

Chrome Security Update Released to Address Code Execution Vulnerabilities

Google has released Chrome 145 to the stable channel for Windows, Mac, and Linux systems, addressing 11 security vulnerabilities that could allow attackers to execute malicious code on affected systems.

The update, announced on February 10, 2026, will roll out gradually over the coming days and weeks.

Critical Security Fixes

The update patches several high-severity vulnerabilities that pose significant risks to users.

The most severe flaw is CVE-2026-2313, a use-after-free vulnerability in CSS that earned researchers an $8,000 bounty.

This type of vulnerability allows attackers to execute arbitrary code by accessing memory after it has been freed.

Two additional high-severity issues were identified by Google’s internal security teams.

CVE-2026-2314 involves a heap buffer overflow in Codecs, while CVE-2026-2315 addresses an inappropriate implementation in WebGPU.

CVE IDSeverityVulnerability TypeReporter
CVE-2026-2313HighUse after freeHan Zheng (HexHive), Wenhao Fang (University of St. Andrews), Qinying Wang (HexHive)
CVE-2026-2314HighHeap buffer overflowGoogle
CVE-2026-2315HighInappropriate implementationGoogle
CVE-2026-2316MediumInsufficient policy enforcementLuan Herrera (@lbherrera_)
CVE-2026-2317MediumInappropriate implementationBrendan Draper
CVE-2026-2318MediumInappropriate implementationShaheen Fazim
CVE-2026-2319MediumRace conditionAnonymous
CVE-2026-2320MediumInappropriate implementationAlesandro Ortiz
CVE-2026-2321MediumUse after freeGoogle
CVE-2026-2322LowInappropriate implementationRobbe Van Roey (PinkDraconian)
CVE-2026-2323LowInappropriate implementationHafiizh

Both vulnerabilities could enable remote code execution if exploited successfully.

The update also resolves six medium-severity vulnerabilities affecting various Chrome components.

CVE-2026-2316, discovered by security researcher Luan Herrera, addresses insufficient policy enforcement in Frames and earned a $5,000 reward.

Other medium-severity fixes target issues in Animation, PictureInPicture, DevTools, File input, and Ozone components.

Two low-severity vulnerabilities (CVE-2026-2322 and CVE-2026-2323) affecting File input and Downloads were also patched, with researchers receiving $1,000 and $500 rewards respectively.

Chrome 145.0.7632.45 is now available for Linux users, while Windows and Mac users will receive versions 145.0.7632.45 or 145.0.7632.46.

The update includes numerous fixes and improvements beyond security patches, with a complete changelog available through the Chromium repository.

Google credits multiple security researchers and its internal teams for discovering these vulnerabilities.

Many bugs were identified using advanced security tools including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL.

The company maintains restricted access to detailed bug information until most users have updated their browsers.

Users should update Chrome immediately by navigating to Settings > About Chrome, where the browser will automatically check for and install the latest version.

Given the severity of the patched vulnerabilities, particularly those enabling code execution, prompt updating is essential to maintain security.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

New RemoveMacAI Tool Removes Apple Intelligence Models and Reclaims Mac Storage

A new open-source command-line utility called RemoveMacAI lets Apple...

Apple Strengthens macOS Privacy Controls as AI Agents Become More Autonomous

Apple has announced plans to strengthen macOS controls for...

Google Gemini to Gain Full Computer Access With New Permission

Google is reportedly testing a new Gemini Desktop feature...

Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads

A critical heap-buffer-overflow vulnerability in libheif could allow authenticated...

Japanese Police Impersonation Scam Operation Dismantled as 16 Suspects Detained in Timor-Leste

Timor-Leste investigators have dismantled a suspected cross-border telecom fraud...

Denmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records

Denmark has confirmed a serious cybersecurity incident involving unauthorized...

CISA Flags Citrix NetScaler Flaw Exploited in Ongoing Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

MediaTek Fixes 31 Security Flaws Affecting Modem, Video and AI Components

MediaTek has released its October 2026 Product Security Bulletin,...

Related Articles

Recent News