TL;DR
Google issued version 153 for its Chrome browser. The release fixes 42 security defects. Three of these flaws carry critical severity ratings. Users should update their browsers without delay.
- Total: 3 CVEs
- Severity: 1 Critical · 1 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 9.6 (Critical · CVSSv3) — CVE-2026-91749
- Action: Apply the latest security updates now
Track every Google CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-91749 | 9.6 | 153.0.8010.47 | Not exploited |
| CVE-2026-91721 | 8.8 | 153.0.8010.47 | Not exploited |
| CVE-2026-91726 | 4.7 | 153.0.8010.47 | Not exploited |
Why This Threat Matters
Over three billion users rely on Google Chrome for daily web browsing. Therefore, browser defects place massive global populations at risk. Attackers frequently exploit browser weaknesses to steal sensitive personal data. If criminals hijack a browser session, they can install secondary malware payloads.
How the Attacks Work
The most severe flaw involves an out-of-bounds read error in the WebGL component. An attacker can craft malicious web pages to trigger this memory corruption. Furthermore, two other critical vulnerabilities cause use-after-free errors. One impacts the Internals component, while the other affects Web Workers.
When a user visits a malicious site, the browser mishandles memory pointers. This failure allows attackers to execute unauthorized commands on the host machine. Currently, Google confirms no active exploitation in the wild for these specific flaws. Furthermore, no public proof-of-concept exploit code exists.
Affected Versions
These vulnerabilities impact older versions of the browser. The flaws affect Chrome installations on Windows, Mac, and Linux systems.
Patch and Mitigation Steps
Users must upgrade to the latest stable release to secure their devices. Google updated the Stable channel to version 153.0.8010.47 for Linux. Windows and Mac users receive version 153.0.8010.47 or .48.
The browser generally applies these patches automatically. However, users should manually verify their version. You can read the full stable channel update details on the official blog. Restart the application to ensure the Google Chrome security update applies correctly.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!