In a significant move to bolster user safety, a new Chrome Stable Channel Update has been launched for desktop users. The update brings the browser version to 146.0.7680.164/165 for Windows and Mac, while Linux users move to 146.0.7680.164. According to the release notes, this critical security deployment will roll out globally over the coming days and weeks.
The core of this release is a suite of 8 security fixes, all of which have been categorized with a “High” severity rating. These vulnerabilities represent a broad spectrum of technical risks, ranging from memory management errors to arithmetic overflows.
Key vulnerabilities addressed in this cycle include:
- Memory Mismanagement: Multiple “Use after free” vulnerabilities were identified in FedCM (CVE-2026-4680), WebGPU (CVE-2026-4678), and the Dawn engine (CVE-2026-4676).
- Buffer Overflows: Heap buffer overflows were discovered and patched in both WebGL (CVE-2026-4675) and WebAudio (CVE-2026-4673).
- Logic and Arithmetic Errors: An Integer overflow in Fonts (CVE-2026-4679) and “Out of bounds reads” in CSS (CVE-2026-4674) and WebAudio (CVE-2026-4677) were also resolved.
While many of the rewards are still “To Be Determined” (TBD), a bounty of $7,000 has already been confirmed for the researcher who reported the WebAudio heap buffer overflow (CVE-2026-4673).
To protect the wider ecosystem, access to specific bug details remains restricted. This is a standard industry practice designed to ensure that a majority of users have updated their systems before the technical blueprints for these exploits are made public. Furthermore, restrictions are held in place if the bug resides in a third-party library that other active projects may still be working to patch.
As these fixes address high-severity threats, users are encouraged to verify that their browsers are up to date. Most desktop browsers will download and apply the update automatically upon restart, but a manual check in the “About” section of your browser settings can ensure you are running the latest, most secure version.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.