Official source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com

Chrome Releases: Stable Channel Update for Desktop

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs26

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-84357Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic
  • CVE-2026-84356UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page
  • CVE-2026-84332Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page
  • CVE-2026-84325Google Chrome: Improper Input Validation
  • CVE-2026-84326Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
  • CVE-2026-84354Google Chrome: Incorrect Authorization
  • CVE-2026-84353Google Chrome: Use After Free
  • CVE-2026-84352Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page
  • CVE-2026-84349Google Chrome: Use After Free
  • CVE-2026-84324Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic
  • CVE-2026-84333Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page
  • CVE-2026-84351Google Chrome: Stack-based Buffer Overflow
  • CVE-2026-84347Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
  • CVE-2026-84334Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program
  • CVE-2026-84335Google Chrome: Incorrect Authorization
  • CVE-2026-84350Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction
  • CVE-2026-84358Google Chrome: Improper Privilege Management
  • CVE-2026-84328Google Chrome: Missing Authorization
  • CVE-2026-84355Google Chrome: Incorrect Authorization
  • CVE-2026-84331Google Chrome: Incorrect Authorization
  • CVE-2026-84330UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page
  • CVE-2026-84359Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page
  • CVE-2026-84323Google Chrome: Missing Authorization
  • CVE-2026-84348Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page
  • CVE-2026-84327Google Chrome: Incorrect Authorization
  • CVE-2026-84329Google Chrome: Unintended Proxy or Intermediary ('Confused Deputy')

Source and provenance

Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗