BlackTreeCVE IntelligenceOfficial source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com
Chrome Releases: Stable Channel Update for Desktop
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 02:48 UTC
Linked CVEs33
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-12466Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page
- CVE-2026-12462Google Chrome — Use After Free
- CVE-2026-12449Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file
- CVE-2026-12448Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to perform privilege escalation via a crafted HTML page
- CVE-2026-12447Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-12443Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page
- CVE-2026-12468Google Chrome — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CVE-2026-12467Google Chrome — Use After Free
- CVE-2026-12465Google Chrome — Improper Input Validation
- CVE-2026-12464Google Chrome — Use After Free
- CVE-2026-12455Google Chrome — Use After Free
- CVE-2026-12454Google Chrome — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CVE-2026-12452Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-12451Google Chrome — Use After Free
- CVE-2026-12445Google Chrome — Use After Free
- CVE-2026-12442Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page
- CVE-2026-12441Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-12440Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-12439Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-12438Google Chrome — Protection Mechanism Failure
- CVE-2026-12437Google Chrome — Use After Free
- CVE-2026-12450Google Chrome — Improper Privilege Management
- CVE-2026-12463Google Chrome — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2026-12460Google Chrome — Improper Access Control
- CVE-2026-12457Google Chrome — Protection Mechanism Failure
- CVE-2026-12469Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-12459Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page
- CVE-2026-12456Google Chrome — Improper Input Validation
- CVE-2026-12453Google Chrome — Improper Input Validation
- CVE-2026-12444Google Chrome — Out-of-bounds Read
- CVE-2026-12446Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-12458Google Chrome — User Interface (UI) Misrepresentation of Critical Information
- CVE-2026-12461Google Chrome — Out-of-bounds Read
Source and provenance
Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 28 Sept 2026, 02:48 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗