BlackTreeCVE IntelligenceOfficial source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com
Chrome Releases: Stable Channel Update for Desktop
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-8558Out of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-8566Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to bypass discretionary access control via a crafted HTML page
- CVE-2026-8563Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page
- CVE-2026-8528Google Chrome — Improper Input Validation
- CVE-2026-8554Google Chrome — Access of Resource Using Incompatible Type ('Type Confusion')
- CVE-2026-8536Google Chrome — Improper Input Validation
- CVE-2026-8562Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-8556Google Chrome — Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2026-8545Google Chrome — Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2026-8537Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-8572Google Chrome — Protection Mechanism Failure
- CVE-2026-8576Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-8578Google Chrome — Out-of-bounds Read
- CVE-2026-8579Google Chrome — Improper Input Validation
- CVE-2026-8586Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control via a malicious file
- CVE-2026-8585Google Chrome — Protection Mechanism Failure
- CVE-2026-8548Google Chrome — Out-of-bounds Write
- CVE-2026-8531Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-8527Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page
- CVE-2026-8526Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-8524Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-8510Google Chrome — External Control of Assumed-Immutable Web Parameter
- CVE-2026-8519Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page
- CVE-2026-8571Google Chrome — Protection Mechanism Failure
- CVE-2026-8569Out of bounds write in Codecs in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file
- CVE-2026-8520Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-8525Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-8534Google Chrome — External Control of Assumed-Immutable Web Parameter
- CVE-2026-8573Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file
- CVE-2026-8575Google Chrome — Use After Free
- CVE-2026-8574Google Chrome — Use After Free
- CVE-2026-8542Google Chrome — Use After Free
- CVE-2026-8533Google Chrome — Use After Free
- CVE-2026-8530Google Chrome — Use After Free
- CVE-2026-8523Google Chrome — Use After Free
- CVE-2026-8515Google Chrome — Use After Free
- CVE-2026-8514Google Chrome — Use After Free
- CVE-2026-8513Google Chrome — Use After Free
- CVE-2026-8512Google Chrome — Use After Free
- CVE-2026-8511Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-8580Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-8547Google Chrome — Missing Authorization
- CVE-2026-8557Google Chrome — Use After Free
- CVE-2026-8540Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-8577Integer overflow in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-8532Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-8529Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file
- CVE-2026-8509Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-8518Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-8521Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic
Source and provenance
Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗