Official source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com

Chrome Releases: Stable Channel Update for Desktop

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 08:35 UTC
Linked CVEs27

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-12026Google Chrome — Out-of-bounds Read
  • CVE-2026-12024Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page
  • CVE-2026-12027Google Chrome — Protection Mechanism Failure
  • CVE-2026-12035Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
  • CVE-2026-12016Google Chrome — Improper Input Validation
  • CVE-2026-12009Google Chrome — Improper Input Validation
  • CVE-2026-12010Google Chrome — Heap-based Buffer Overflow
  • CVE-2026-12019Google Chrome — Out-of-bounds Write
  • CVE-2026-12018Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file
  • CVE-2026-12031Google Chrome — Protection Mechanism Failure
  • CVE-2026-12030Google Chrome — Heap-based Buffer Overflow
  • CVE-2026-12022Google Chrome — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
  • CVE-2026-12007Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML page
  • CVE-2026-12008Google Chrome — Use After Free
  • CVE-2026-12034Google Chrome — Improper Input Validation
  • CVE-2026-12012Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic
  • CVE-2026-12014Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic
  • CVE-2026-12020Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
  • CVE-2026-12023Google Chrome — Use After Free
  • CVE-2026-12028Google Chrome — Use After Free
  • CVE-2026-12029Google Chrome — Use After Free
  • CVE-2026-12017Google Chrome — Improper Input Validation
  • CVE-2026-12032Google Chrome — Origin Validation Error
  • CVE-2026-12025Google Chrome — Improper Input Validation
  • CVE-2026-12033Google Chrome — Out-of-bounds Read
  • CVE-2026-12011Google Chrome — Use After Free
  • CVE-2026-12015Google Chrome — Use After Free

Source and provenance

Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 28 Sept 2026, 08:35 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗