Chrome 152: Google fixes 26 vulnerabilities, including two critical ones

Published Reading time: 3 minutes Vulnerabilities & Security Updates

Google has released Chrome versions 152.0.7977.75/.76 for Windows and macOS, and Chrome version 152.0.7977.75 for Linux. The update fixes a total of 26 security vulnerabilities in the browser.

Chrome 152: Google fixes 26 vulnerabilities, including two critical ones - Image 1

These include two critical use-after-free vulnerabilities, affecting Shared Tab Groups and WebGL. Google has not disclosed whether any of the vulnerabilities are already being used in real attacks.

Google Fixes 26 Chrome Vulnerabilities

The update is rolling out to the Stable channel and is expected to reach users in the coming days and weeks. It is recommended for both personal users and organizations managing Chrome devices.

The two critical vulnerabilities

The two most serious vulnerabilities are listed as CVE-2026-84353 and CVE-2026-84352. The first concerns use-after-free in Shared Tab Groups and the second concerns WebGL, Chrome's technology for displaying interactive 2D and 3D graphics.

A use-after-free vulnerability occurs when a program continues to use a memory area after it has been freed. If an attacker manages to manipulate this memory, it could cause data corruption, a browser crash, information leakage, or code execution.

WebGL vulnerabilities are particularly important because they can be exploited via web applications, advertisements, or malicious websites that use graphics features. With properly crafted web content, an attacker could cause Chrome to crash or gain control within the browser process.

The remaining corrections

The update also includes several high-severity vulnerabilities:

  • CVE-2026-84354 in the FileSystem, due to incorrect authorization check.
  • CVE-2026-84359 in Skia, which could cause information to leak.
  • CVE-2026-84357 in the Omnibox, due to insufficient input control.
  • CVE-2026-84324 in Proxy, CVE-2026-84349 in the Browser and CVE-2026-84333 at Dawn, all use-after-free type.
  • CVE-2026-84326 in the V8 JavaScript engine, due to an uninitialized resource.
  • CVE-2026-84351 on the GPU, due to a buffer overflow.
  • CVE-2026-84325 in DataTransfer, due to insufficient input control.

The following medium severity vulnerabilities were also fixed: CVE-2026-84328 and CVE-2026-84323 in FileSystem, CVE-2026-84347 in WebRTC, CVE-2026-84355 in Navigation, CVE-2026-84358 in Downloads, CVE-2026-84332 in SiteSettings, CVE-2026-84330 in FullScreen, CVE-2026-84334 in Chromoting, CVE-2026-84348 in MediaCapture, and CVE-2026-84335 in TabStrip.

Low severity fixes include CVE-2026-84327 in Autofill, CVE-2026-84329 in CredentialProvider, CVE-2026-84356 in FullScreen, CVE-2026-84350 in TabStrip, and CVE-2026-84331 in Actor.

Google said it may temporarily restrict access to bug reports and technical details until the majority of users have installed the update, reducing the risk that attackers could exploit publicly available information before the updates are fully installed.

The company credited internal teams and external security researchers for identifying the issues, and said it uses technologies such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL when checking the code.

Users can check if an update is available by opening Chrome and selecting Settings → About Chrome . The browser will search for and download the latest version. Organizations should ensure that managed devices receive version 152.0.7977.75 or later as the rollout completes.

Hacks.gr on Google Set it as a preferred source for cybersecurity updates.
Preferred source

READ ALSO

Recommended readings from Hacks.gr to continue.

Participate in the discussion

Comments should remain on topic. Your email address will not be published.

0 / 2000

0 / 50

Your comments will not be published if:

  • 1. They cause "DoS" to the community with irrelevant or repetitive comments.
  • 2. They try to "phish" other users' information.
  • 3. They contain "zero-day" insults and slurs.
  • 4. Contain "malware" advertisements for products or services.
  • 5. Your comments should be sweet and friendly, not like malicious cookies trying to mislead us!