Official source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com

Chrome Releases: Stable Channel Update for Desktop

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs21

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-5272Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page
  • CVE-2026-5287Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file
  • CVE-2026-5273Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-5285Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-5279Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-5275Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page
  • CVE-2026-5274Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page
  • CVE-2026-5277Google Chrome — External Control of Assumed-Immutable Web Parameter
  • CVE-2026-5278Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page
  • CVE-2026-5280Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-5284Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page
  • CVE-2026-5286Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page
  • CVE-2026-5288Google Chrome — Use After Free
  • CVE-2026-5289Google Chrome — Use After Free
  • CVE-2026-5290Google Chrome — Use After Free
  • CVE-2026-5292Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page
  • CVE-2026-5281Google Dawn Use-After-Free Vulnerability
  • CVE-2026-5283Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page
  • CVE-2026-5291Google Chrome — Exposure of Sensitive Information to an Unauthorized Actor
  • CVE-2026-5282Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page
  • CVE-2026-5276Google Chrome — Protection Mechanism Failure

Source and provenance

Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗