Saturday, August 22, 2026

Google Issues Urgent Chrome Security Update for Exploited Zero-Day Flaw

Google has released an urgent security update for its Chrome browser, addressing multiple vulnerabilities, including a zero-day flaw actively exploited in the wild. The update upgrades Chrome to version 149.0.7827.102/.103 on Windows and Mac, and to 149.0.7827.102 on Linux.

The tech giant confirmed that the zero-day vulnerability, tracked as CVE-2026-11645, involves an out-of-bounds memory access issue in the V8 JavaScript engine. Although classified as a high-severity flaw, its active exploitation significantly increases the risk, allowing attackers to execute arbitrary code via crafted web content.

Chrome Security Update

In total, Google patched 74 security vulnerabilities in this release, with a large portion categorized as critical severity. Most of these critical flaws stem from “use-after-free” memory corruption issues across various Chrome components, including Ozone, Bluetooth, TabStrip, Views, and Web Apps.

These vulnerabilities can lead to heap corruption and, if successfully exploited, could be leveraged for remote code execution.

Google has restricted detailed technical information about these vulnerabilities to prevent further exploitation until a majority of users have applied the update. The company also noted that some bugs may exist in third-party libraries, which could delay full disclosure.

Security researchers and internal teams reported the majority of the flaws in late May 2026. Google credited its advanced bug detection systems, including AddressSanitizer, MemorySanitizer, and libFuzzer, for identifying several of these issues during testing.

The presence of an actively exploited vulnerability highlights the urgency for users and organizations to update their browsers immediately. Threat actors often weaponize these flaws in drive-by download attacks or through malicious websites, leaving unpatched systems highly vulnerable.

Critical CVEs Patched

CVE IDVulnerability TypeComponentReported Date
CVE-2026-11628Use-after-freeOzone2026-05-25
CVE-2026-11629Use-after-freeOzone2026-05-26
CVE-2026-11630Use-after-freeFile Input2026-05-26
CVE-2026-11631Use-after-freeAura2026-05-26
CVE-2026-11632Use-after-freeTabStrip2026-05-26
CVE-2026-11633Use-after-freeBluetooth2026-05-27
CVE-2026-11634Use-after-freeGamepad2026-05-27
CVE-2026-11635Use-after-freeBluetooth2026-05-27
CVE-2026-11636Use-after-freeAutofill2026-05-27
CVE-2026-11637Use-after-freeViews2026-05-27
CVE-2026-11638Use-after-freePrinting2026-05-27
CVE-2026-11639Use-after-freeCompositing2026-05-27
CVE-2026-11640Integer overflowlibyuv2026-05-28
CVE-2026-11641Use-after-freeBluetooth2026-05-28
CVE-2026-11642Use-after-freeWeb Apps2026-05-29
CVE-2026-11643Use-after-freeProxy2026-05-29
CVE-2026-11644Use-after-freeViews2026-05-30

Users are strongly advised to update Chrome via Settings > About Chrome to ensure they are protected against these vulnerabilities. Organizations should prioritize patch management and monitor for any signs of exploitation, particularly related to the V8 engine flaw.

Given the scale and severity of the patched issues, this update is critical for maintaining browser security and preventing potential compromise.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks

A Chinese-speaking threat actor has been observed using DeepSeek...

Zero-Click Grok Attack Lets Hackers Steal Chat History Using Encrypted Prompt Injection

A newly disclosed prompt-injection technique could turn a routine...

768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts

A large-scale investigation has uncovered 768 publicly exposed AWS...

Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts

Investment fraud is increasingly exploiting the one action banks...

UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft

A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable...

Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access

Cybersecurity researchers have revealed a critical vulnerability in N-able’s...

Related Articles

Recent News