Monday, September 7, 2026

Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks

Google has released a Chrome security update that addresses 12 high-severity vulnerabilities affecting various components, including WebAudio, ANGLE, Chromecast, extensions, Skia, the V8 JavaScript engine, certificate handling, the user interface, and GPU elements.

Many of these vulnerabilities involve memory corruption issues, such as out-of-bounds reads and writes, use-after-free bugs, stack buffer overflows, and type confusion. Attackers commonly exploit these flaws to gain code execution, bypass security boundaries, or cause browser crashes.

Google Chrome Update Fixes 12 Flaws

The Stable Channel release is version 150.0.7871.181/.182 for Windows and macOS, while Linux users will receive version 150.0.7871.181. Administrators should prioritize deploying this update across managed devices, especially those that access untrusted websites, web applications, external documents, or embedded browser content.

Users can manually check their installed version by navigating to Chrome Menu → Help → About Google Chrome, which will trigger the update process and often require a browser restart to activate the patched version.

Two externally reported vulnerabilities affecting the WebAudio API have been identified: CVE-2026-16420, which involves type confusion, and CVE-2026-16421, related to an improper implementation in WebAudio.

These vulnerabilities were found by XBOW and triaged by Brendan Dolan-Gavitt, with Google awarding $500 for each report. Type confusion can occur when software misinterprets an object as an incompatible type, potentially allowing attackers to manipulate memory unexpectedly.

The other vulnerabilities, reported internally by Google, impact critical rendering and execution pathways. The update resolves an out-of-bounds write and a separate out-of-bounds read-and-write flaw in ANGLE, which is Chromium’s graphics translation layer.

It also addresses a stack buffer overflow in V8, Chrome’s JavaScript and WebAssembly engine, in addition to use-after-free vulnerabilities in the user interface and GPU components.

Such vulnerabilities can be particularly dangerous since attacker-controlled web content may exploit affected code through JavaScript, graphics operations, media processing, or specially crafted web pages.

While Google has not confirmed any active exploitation of the 12 vulnerabilities in the wild, the company has restricted the disclosure of specific bug details and issue links until most Chrome users have received the update.

This is a standard defensive measure aimed at reducing the window for potential exploitation before the adoption of the patch increases. Additionally, restrictions may remain in place if a vulnerability impacts third-party components that require coordinated remediation.

CVESeverityVulnerability TypeAffected ComponentReporter
CVE-2026-16413HighOut-of-bounds writeANGLEGoogle
CVE-2026-16414HighInsufficient validation of untrusted inputChromecastGoogle
CVE-2026-16415HighInsufficient validation of untrusted inputExtensionsGoogle
CVE-2026-16416HighInteger overflowChromecastGoogle
CVE-2026-16417HighUninitialized useSkiaGoogle
CVE-2026-16418HighStack buffer overflowV8Google
CVE-2026-16419HighOut-of-bounds read and writeANGLEGoogle
CVE-2026-16420HighType confusionWebAudioXBOW
CVE-2026-16421HighInappropriate implementationWebAudioXBOW
CVE-2026-16422HighInsufficient validation of untrusted inputCertificateGoogle
CVE-2026-16423HighUse-after-freeUIGoogle
CVE-2026-16424HighUse-after-freeGPUGoogle

Google credited its security hardening and bug-finding initiatives, including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL, for helping identify security defects during development.

Organizations are advised to enforce rapid browser patching, verify version compliance through endpoint management tools, and ensure that Chromium-based browsers receive vendor-specific updates as necessary.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron

CrowdStrike has launched SafeMind, an AI-driven cybersecurity system developed...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Related Articles

Recent News