BlackTreeCVE IntelligenceOfficial source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com
Chrome Releases: Stable Channel Update for Desktop
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 14:38 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-11640Google Chrome — External Control of Assumed-Immutable Web Parameter
- CVE-2026-11682Google Chrome — Improper Input Validation
- CVE-2026-11677Google Chrome — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CVE-2026-11672Google Chrome — Out-of-bounds Write
- CVE-2026-11655Google Chrome — External Control of Assumed-Immutable Web Parameter
- CVE-2026-11659Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-11661Google Chrome — Use After Free
- CVE-2026-11654Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-11631Google Chrome — Use After Free
- CVE-2026-11660Google Chrome — Improper Input Validation
- CVE-2026-11676Google Chrome — Improper Input Validation
- CVE-2026-11697Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-11667Google Chrome — Out-of-bounds Read
- CVE-2026-11636Google Chrome — Use After Free
- CVE-2026-11629Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-11630Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-11648Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-11664Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-11681Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-11645Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
- CVE-2026-11689Google Chrome — Improper Input Validation
- CVE-2026-11653Google Chrome — Improper Input Validation
- CVE-2026-11658Google Chrome — Improper Input Validation
- CVE-2026-11693Google Chrome — Origin Validation Error
- CVE-2026-11701Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page
- CVE-2026-11666Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page
- CVE-2026-11651Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-11638Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-11634Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-11635Google Chrome — Use After Free
- CVE-2026-11642Google Chrome — Use After Free
- CVE-2026-11647Google Chrome — Use After Free
- CVE-2026-11652Google Chrome — Use After Free
- CVE-2026-11656Google Chrome — Use After Free
- CVE-2026-11663Google Chrome — Use After Free
- CVE-2026-11671Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-11679Google Chrome — Use After Free
- CVE-2026-11692Google Chrome — Use After Free
- CVE-2026-11700Google Chrome — Use After Free
- CVE-2026-11687Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-11698Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-11699Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-11662Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-11650Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-11649Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-11643Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic
- CVE-2026-11632Google Chrome — Use After Free
- CVE-2026-11633Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral
- CVE-2026-11637Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page
- CVE-2026-11639Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page
Source and provenance
Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 28 Sept 2026, 14:38 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗