These include two critical use-after-free vulnerabilities, affecting Shared Tab Groups and WebGL. Google has not disclosed whether any of the vulnerabilities are already being used in real attacks.

The update is rolling out to the Stable channel and is expected to reach users in the coming days and weeks. It is recommended for both personal users and organizations managing Chrome devices.
The two critical vulnerabilities
The two most serious vulnerabilities are listed as CVE-2026-84353 and CVE-2026-84352. The first concerns use-after-free in Shared Tab Groups and the second concerns WebGL, Chrome's technology for displaying interactive 2D and 3D graphics.
A use-after-free vulnerability occurs when a program continues to use a memory area after it has been freed. If an attacker manages to manipulate this memory, it could cause data corruption, a browser crash, information leakage, or code execution.
WebGL vulnerabilities are particularly important because they can be exploited via web applications, advertisements, or malicious websites that use graphics features. With properly crafted web content, an attacker could cause Chrome to crash or gain control within the browser process.
The remaining corrections
The update also includes several high-severity vulnerabilities:
- CVE-2026-84354 in the FileSystem, due to incorrect authorization check.
- CVE-2026-84359 in Skia, which could cause information to leak.
- CVE-2026-84357 in the Omnibox, due to insufficient input control.
- CVE-2026-84324 in Proxy, CVE-2026-84349 in the Browser and CVE-2026-84333 at Dawn, all use-after-free type.
- CVE-2026-84326 in the V8 JavaScript engine, due to an uninitialized resource.
- CVE-2026-84351 on the GPU, due to a buffer overflow.
- CVE-2026-84325 in DataTransfer, due to insufficient input control.
The following medium severity vulnerabilities were also fixed: CVE-2026-84328 and CVE-2026-84323 in FileSystem, CVE-2026-84347 in WebRTC, CVE-2026-84355 in Navigation, CVE-2026-84358 in Downloads, CVE-2026-84332 in SiteSettings, CVE-2026-84330 in FullScreen, CVE-2026-84334 in Chromoting, CVE-2026-84348 in MediaCapture, and CVE-2026-84335 in TabStrip.
Low severity fixes include CVE-2026-84327 in Autofill, CVE-2026-84329 in CredentialProvider, CVE-2026-84356 in FullScreen, CVE-2026-84350 in TabStrip, and CVE-2026-84331 in Actor.
Google said it may temporarily restrict access to bug reports and technical details until the majority of users have installed the update, reducing the risk that attackers could exploit publicly available information before the updates are fully installed.
The company credited internal teams and external security researchers for identifying the issues, and said it uses technologies such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL when checking the code.
Users can check if an update is available by opening Chrome and selecting Settings → About Chrome . The browser will search for and download the latest version. Organizations should ensure that managed devices receive version 152.0.7977.75 or later as the rollout completes.
Your comments will not be published if: