TL;DR
Google released Chrome version 152.0.7977.75 to fix 26 security flaws. These critical Google Chrome vulnerabilities, including CVE-2026-84353, allow attackers to corrupt memory and execute code. Therefore, users must update their browsers immediately to prevent breaches.
- Total: 5 CVEs
- Severity: 5 Unrated
- Actively exploited: None confirmed
- Highest severity: Awaiting analysis — CVE-2026-84353
- Action: Apply the latest security updates now
Notable CVEs
| CVE | Type | Fixed in | Status |
|---|---|---|---|
| CVE-2026-84353 | CWE-416 | 152.0.7977.75 | Not exploited |
| CVE-2026-84352 | CWE-416 | 152.0.7977.75 | Not exploited |
| CVE-2026-84354 | CWE-863 | 152.0.7977.75 | Not exploited |
| CVE-2026-84359 | CWE-200 | 152.0.7977.75 | Not exploited |
| CVE-2026-84357 | CWE-20 | 152.0.7977.75 | Not exploited |
Why It Matters
Chrome holds an estimated 69 percent global desktop market share based on industry sources. Consequently, over 3 billion people rely on this browser globally. These Google Chrome vulnerabilities expose an enormous attack surface for threat actors. Hackers can exploit these flaws to compromise enterprise networks completely. Furthermore, successful attacks can lead to severe data theft. Unpatched browsers present an immediate danger to corporate and personal privacy alike. Organizations must treat this update as a high priority.
How the Attack Works
The update patches multiple severe “use after free” errors. Specifically, these memory corruption flaws exist in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352). An attacker creates a highly malicious webpage to trigger the bug. Next, they trick the victim into visiting this crafted site. The browser then mishandles memory allocation during the browsing session. As a result, the attacker can execute arbitrary code silently. The exploit requires no additional interaction from the victim. Additionally, other flaws involve improper input validation in the Omnibox.
Affected Versions
These bugs impact all Chrome stable channel releases prior to 152.0.7977.75. Currently, Google has not confirmed any active exploitation in the wild. Moreover, security researchers have not published any public proof-of-concept code. Google intentionally limits technical information to protect users. The advisory states, “Access to bug details and links may be kept restricted until a majority of users are updated with a fix.”
Patch or Mitigation Steps
You must update your browser to the latest version immediately. Specifically, the secure releases are 152.0.7977.75/.76 for Windows and Mac, and 152.0.7977.75 for Linux. Simply restart Chrome to apply the pending software update. For complete details, read the official stable channel update for desktop. Finally, system administrators should force this update across all corporate endpoints. Verifying the installation ensures that your network remains secure against these threats.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!