Friday, September 11, 2026

Critical Chrome Flaws Let Attackers Execute Arbitrary Code

Google has released an urgent security update for its Chrome browser, resolving multiple dangerous vulnerabilities.

The Chrome team promoted version 147 to the stable channel for Windows, Mac, and Linux users on April 7, 2026.

This major release patches flaws that could allow attackers to execute arbitrary code and take full control of affected systems. The update is currently rolling out to all users globally over the coming days and weeks.

The most severe threats in this update are two critical vulnerabilities located in the WebML component. Tracked as CVE-2026-5858 and CVE-2026-5859, these flaws involve heap buffer and integer overflows.

Because of the high risk they pose, Google awarded massive $43,000 bug bounties to the security researchers who discovered them.

These critical bugs can be exploited simply by tricking a user into visiting a specially crafted webpage, making immediate patching absolutely essential.

Beyond the critical flaws, Chrome 147 addresses numerous high-severity bugs spread across several key browser components.

Security researchers found serious issues like use-after-free errors, type confusion, and out-of-bounds read and write flaws in the V8 JavaScript engine, WebRTC, Media, Blink, and Skia.

If exploited, these vulnerabilities could cause the browser to crash or allow malicious actors to compromise the underlying system.

Google paid tens of thousands of dollars in rewards to the ethical hackers who reported these issues to prevent them from falling into the wrong hands.

To protect users, Google will keep the technical details and exploit methods for these vulnerabilities strictly restricted.

This coordinated disclosure policy guarantees that the majority of the public has enough time to install the security patch before cybercriminals can reverse-engineer the fixes.

It also protects other software projects that depend on the same vulnerable third-party libraries, ensuring that the wider tech ecosystem remains secure while patches are developed and deployed.

Due to the severe nature of the WebML flaws, individuals and enterprise administrators are strongly advised to update their browsers immediately.

You can force the update manually by opening the Chrome menu, navigating to Help, and selecting About Google Chrome.

The browser will automatically download version 147.0.7727.55 for Linux or 147.0.7727.55/56 for Windows and Mac, securing your device against potential cyberattacks.

Chrome 147 Security Fixes

CVE IDSeverityComponentVulnerability Type
CVE-2026-5858CriticalWebMLHeap buffer overflow
CVE-2026-5859CriticalWebMLInteger overflow
CVE-2026-5860HighWebRTCUse after free
CVE-2026-5861HighV8Use after free
CVE-2026-5862HighV8Inappropriate implementation
CVE-2026-5863HighV8Inappropriate implementation
CVE-2026-5864HighWebAudioHeap buffer overflow
CVE-2026-5865HighV8Type Confusion
CVE-2026-5866HighMediaUse after free
CVE-2026-5867HighWebMLHeap buffer overflow
CVE-2026-5868HighANGLEHeap buffer overflow
CVE-2026-5869HighWebMLHeap buffer overflow
CVE-2026-5870HighSkiaInteger overflow
CVE-2026-5871HighV8Type Confusion
CVE-2026-5872HighBlinkUse after free
CVE-2026-5873HighV8Out of bounds read and write
CVE-2026-5874MediumPrivateAIUse after free
CVE-2026-5875MediumBlinkPolicy bypass
CVE-2026-5876MediumNavigationSide-channel information leakage
CVE-2026-5877MediumNavigationUse after free
CVE-2026-5878MediumBlinkIncorrect security UI
CVE-2026-5879MediumANGLEInsufficient validation of untrusted input
CVE-2026-5880Mediumbrowser UIIncorrect security UI
CVE-2026-5881MediumLocalNetworkAccessPolicy bypass
CVE-2026-5882MediumFullscreenIncorrect security UI
CVE-2026-5883MediumMediaUse after free
CVE-2026-5884MediumMediaInsufficient validation of untrusted input
CVE-2026-5885MediumWebMLInsufficient validation of untrusted input
CVE-2026-5886MediumWebAudioOut of bounds read
CVE-2026-5887MediumDownloadsInsufficient validation of untrusted input
CVE-2026-5888MediumWebCodecsUninitialized Use
CVE-2026-5889MediumPDFiumCryptographic Flaw
CVE-2026-5890MediumWebCodecsRace
CVE-2026-5891Mediumbrowser UIInsufficient policy enforcement
CVE-2026-5892MediumPWAsInsufficient policy enforcement
CVE-2026-5893MediumV8Race
CVE-2026-5894LowPDFInappropriate implementation
CVE-2026-5895LowOmniboxIncorrect security UI
CVE-2026-5896LowAudioPolicy bypass
CVE-2026-5897LowDownloadsIncorrect security UI
CVE-2026-5898LowOmniboxIncorrect security UI
CVE-2026-5899LowHistory NavigationIncorrect security UI
CVE-2026-5900LowDownloadsPolicy bypass
CVE-2026-5901LowDevToolsPolicy bypass
CVE-2026-5902LowMediaRace
CVE-2026-5903LowIFrameSandboxPolicy bypass
CVE-2026-5904LowV8Use after free
CVE-2026-5905LowPermissionsIncorrect security UI
CVE-2026-5906LowOmniboxIncorrect security UI
CVE-2026-5907LowMediaInsufficient data validation
CVE-2026-5908LowMediaInteger overflow
CVE-2026-5909LowMediaInteger overflow
CVE-2026-5910LowMediaInteger overflow
CVE-2026-5911LowServiceWorkersPolicy bypass
CVE-2026-5912LowWebRTCInteger overflow
CVE-2026-5913LowBlinkOut of bounds read
CVE-2026-5914LowCSSType Confusion
CVE-2026-5915LowWebMLInsufficient validation of untrusted input
CVE-2026-5918LowNavigationInappropriate implementation
CVE-2026-5919LowWebSocketsInsufficient validation of untrusted input

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News