BlackTreeCVE IntelligenceOfficial source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com
Chrome Releases: Stable Channel Update for Desktop
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-17909Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via malicious network traffic
- CVE-2026-82072Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-17735Google Chrome — Improper Input Validation
- CVE-2026-17913Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page
- CVE-2026-17841Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page
- CVE-2026-17729Google Chrome — Use After Free
- CVE-2026-17738Google Chrome — Improper Input Validation
- CVE-2026-17743Insufficient policy enforcement in ControlledFrame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-17748Google Chrome — Origin Validation Error
- CVE-2026-17749Google Chrome — Improper Input Validation
- CVE-2026-17754Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-17755Google Chrome — User Interface (UI) Misrepresentation of Critical Information
- CVE-2026-17787Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-17756Insufficient policy enforcement in Presentation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page
- CVE-2026-17761Google Chrome — Improper Input Validation
- CVE-2026-17764Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-17768Google Chrome — Improper Input Validation
- CVE-2026-17784Google Chrome — Use After Free
- CVE-2026-17789Google Chrome — Improper Input Validation
- CVE-2026-17791Google Chrome — Improper Input Validation
- CVE-2026-17854Insufficient policy enforcement in WebMCP in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-17855Google Chrome — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CVE-2026-17856Google Chrome — Protection Mechanism Failure
- CVE-2026-17865Google Chrome — Protection Mechanism Failure
- CVE-2026-17860Google Chrome — Improper Input Validation
- CVE-2026-17869Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page
- CVE-2026-17873Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page
- CVE-2026-17882Google Chrome — Protection Mechanism Failure
- CVE-2026-17883Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-17901Google Chrome — Improper Input Validation
- CVE-2026-17912Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page
- CVE-2026-17925Inappropriate implementation in Cast in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-17852Inappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-17850Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-17849Google Chrome — User Interface (UI) Misrepresentation of Critical Information
- CVE-2026-17848Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file
- CVE-2026-17847Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-17853Google Chrome — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2026-17846Google Chrome — Origin Validation Error
- CVE-2026-17780Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page
- CVE-2026-17779Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page
- CVE-2026-17776Google Chrome — Protection Mechanism Failure
- CVE-2026-17782Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page
- CVE-2026-17772Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page
- CVE-2026-17770Google Chrome — Out-of-bounds Read
- CVE-2026-17792Inappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page
- CVE-2026-17793Inappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page
- CVE-2026-17794Google Chrome — Improper Input Validation
- CVE-2026-17887Google Chrome — Use After Free
- CVE-2026-17828Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page
Source and provenance
Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗