Official source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com

Chrome Releases: Stable Channel Update for Desktop

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 02:48 UTC
Linked CVEs18

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-13022Google Chrome — Origin Validation Error
  • CVE-2026-13037Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-13036Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-13031Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-13029Google Chrome — Use After Free
  • CVE-2026-13027Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
  • CVE-2026-13026Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
  • CVE-2026-13025Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-13038Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page
  • CVE-2026-13033Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page
  • CVE-2026-13032Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-13028Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-13035Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral
  • CVE-2026-13030Google Chrome — Use of Uninitialized Variable
  • CVE-2026-13024Google Chrome — Improper Input Validation
  • CVE-2026-13023Google Chrome — Use of Uninitialized Variable
  • CVE-2026-13034Google Chrome — Origin Validation Error
  • CVE-2026-13021Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page

Source and provenance

Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 28 Sept 2026, 02:48 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗