Official source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com

Chrome Releases: Stable Channel Update for Desktop

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 20:28 UTC
Linked CVEs50

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-10022Google Chrome — Access of Resource Using Incompatible Type ('Type Confusion')
  • CVE-2026-10002Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file
  • CVE-2026-9990Google Chrome — Use After Free
  • CVE-2026-9965Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
  • CVE-2026-9961Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
  • CVE-2026-9958Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file
  • CVE-2026-9954Google Chrome — Use After Free
  • CVE-2026-9940Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
  • CVE-2026-9923Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
  • CVE-2026-9887Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script
  • CVE-2026-9964Google Chrome — Use After Free
  • CVE-2026-9999Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
  • CVE-2026-9892Google Chrome — Improper Privilege Management
  • CVE-2026-9918Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-9972Google Chrome — Use of Uninitialized Variable
  • CVE-2026-10020Google Chrome — Improper Input Validation
  • CVE-2026-9982Google Chrome — Improper Input Validation
  • CVE-2026-9977Google Chrome — Improper Input Validation
  • CVE-2026-9914Google Chrome — Improper Input Validation
  • CVE-2026-9898Google Chrome — Improper Input Validation
  • CVE-2026-9885Google Chrome — Improper Input Validation
  • CVE-2026-9880Google Chrome — Improper Input Validation
  • CVE-2026-9915Google Chrome — Heap-based Buffer Overflow
  • CVE-2026-9924Google Chrome — Heap-based Buffer Overflow
  • CVE-2026-9926Google Chrome — Heap-based Buffer Overflow
  • CVE-2026-9872Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-9900Google Chrome — Out-of-bounds Write
  • CVE-2026-9906Google Chrome — Out-of-bounds Write
  • CVE-2026-9916Google Chrome — Out-of-bounds Write
  • CVE-2026-9967Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-9974Google Chrome — Out-of-bounds Write
  • CVE-2026-9975Google Chrome — Out-of-bounds Read
  • CVE-2026-9875Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-9889Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-9895Google Chrome — Out-of-bounds Read
  • CVE-2026-10017Google Chrome — Out-of-bounds Read
  • CVE-2026-9966Google Chrome — External Control of Assumed-Immutable Web Parameter
  • CVE-2026-9998Google Chrome — External Control of Assumed-Immutable Web Parameter
  • CVE-2026-9876Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-9893Google Chrome — Use After Free
  • CVE-2026-9948Google Chrome — Use After Free
  • CVE-2026-9988Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-9874Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-9877Google Chrome — Use After Free
  • CVE-2026-9881Google Chrome — Use After Free
  • CVE-2026-9886Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
  • CVE-2026-9888Google Chrome — Use After Free
  • CVE-2026-9890Google Chrome — Use After Free
  • CVE-2026-9891Google Chrome — Use After Free
  • CVE-2026-9894Google Chrome — Use After Free

Source and provenance

Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 28 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗