BlackTreeCVE IntelligenceOfficial source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com
Chrome Releases: Stable Channel Update for Desktop
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 14:38 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-11029Google Chrome — Improper Input Validation
- CVE-2026-11005Google Chrome — Out-of-bounds Read
- CVE-2026-11146Google Chrome — Improper Input Validation
- CVE-2026-11139Inappropriate implementation in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-11131Google Chrome — Use After Free
- CVE-2026-11120Google Chrome — Improper Input Validation
- CVE-2026-11121Google Chrome — Improper Input Validation
- CVE-2026-11123Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page
- CVE-2026-11137Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page
- CVE-2026-11138Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-11140Google Chrome — Improper Input Validation
- CVE-2026-11141Google Chrome — Use of Uninitialized Variable
- CVE-2026-11143Google Chrome — Heap-based Buffer Overflow
- CVE-2026-11144Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file
- CVE-2026-11145Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-11119Google Chrome — Improper Input Validation
- CVE-2026-11116Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic
- CVE-2026-11115Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file
- CVE-2026-11114Google Chrome — Use After Free
- CVE-2026-11113Google Chrome — Improper Input Validation
- CVE-2026-11112Google Chrome — Improper Input Validation
- CVE-2026-11111Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page
- CVE-2026-11110Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-11109Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-11105Google Chrome — Improper Input Validation
- CVE-2026-11104Google Chrome — Use of Uninitialized Variable
- CVE-2026-11101Uninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-11098Google Chrome — Improper Input Validation
- CVE-2026-10973Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-10972Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-10968Google Chrome — Improper Input Validation
- CVE-2026-10966Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file
- CVE-2026-10955Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page
- CVE-2026-11126Google Chrome — Improper Input Validation
- CVE-2026-11124Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-11128Google Chrome — Improper Input Validation
- CVE-2026-10995Google Chrome — Heap-based Buffer Overflow
- CVE-2026-10996Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page
- CVE-2026-10997Google Chrome — Incorrect Permission Assignment for Critical Resource
- CVE-2026-11019Google Chrome — Authentication Bypass by Spoofing
- CVE-2026-11007Google Chrome — Improper Input Validation
- CVE-2026-11008Google Chrome — Improper Input Validation
- CVE-2026-11011Google Chrome — Client-Side Enforcement of Server-Side Security
- CVE-2026-11014Google Chrome — Client-Side Enforcement of Server-Side Security
- CVE-2026-11127Inappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted WebAPK
- CVE-2026-11122Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page
- CVE-2026-11015Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page
- CVE-2026-11013Google Chrome — Improper Input Validation
- CVE-2026-11018Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page
- CVE-2026-11021Google Chrome — Improper Input Validation
Source and provenance
Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 28 Sept 2026, 14:38 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗