Official source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com

Chrome Releases: Stable Channel Update for Desktop

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs41

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-19147Google Chrome — Use After Free
  • CVE-2026-19144Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
  • CVE-2026-19158Google Chrome — Use After Free
  • CVE-2026-19159Google Chrome — Use After Free
  • CVE-2026-19142Google Chrome — Use After Free
  • CVE-2026-19156Google Chrome — Heap-based Buffer Overflow
  • CVE-2026-19175Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-19173Google Chrome — Out-of-bounds Write
  • CVE-2026-19171Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-19166Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-19164Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-19152Google Chrome — Protection Mechanism Failure
  • CVE-2026-19148Google Chrome — Out-of-bounds Write
  • CVE-2026-19143Google Chrome — Improper Input Validation
  • CVE-2026-19141Google Chrome — Use After Free
  • CVE-2026-19153Google Chrome — Improper Input Validation
  • CVE-2026-19167Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page
  • CVE-2026-19157Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-19140Google Chrome — Use After Free
  • CVE-2026-19151Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-19155Google Chrome — Use After Free
  • CVE-2026-19163Google Chrome — Use After Free
  • CVE-2026-19177Google Chrome — Improper Input Validation
  • CVE-2026-19165Google Chrome — Use After Free
  • CVE-2026-19176Google Chrome — Use After Free
  • CVE-2026-19174Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-19145Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-19150Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-19162Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-19139Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file
  • CVE-2026-19138Google Chrome — Heap-based Buffer Overflow
  • CVE-2026-19168Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-19169Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page
  • CVE-2026-19172Google Chrome — Use After Free
  • CVE-2026-19170Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-19154Google Chrome — Use After Free
  • CVE-2026-19149Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-19137Google Chrome — Use After Free
  • CVE-2026-19160Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page
  • CVE-2026-19146Google Chrome — Use of Uninitialized Variable
  • CVE-2026-19161Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page

Source and provenance

Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗