BlackTreeCVE IntelligenceOfficial source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com
Chrome Releases: Stable Channel Update for Desktop
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 16:54 UTC
Linked CVEs42
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-91723Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page
- CVE-2026-91732Google Chrome: Missing Authorization
- CVE-2026-91742Google Chrome: Unintended Proxy or Intermediary ('Confused Deputy')
- CVE-2026-91719Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page
- CVE-2026-91726Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page
- CVE-2026-91738Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page
- CVE-2026-91748Google Chrome: Time-of-check Time-of-use (TOCTOU) Race Condition
- CVE-2026-91712Google Chrome: Time-of-check Time-of-use (TOCTOU) Race Condition
- CVE-2026-91743Google Chrome: Time-of-check Time-of-use (TOCTOU) Race Condition
- CVE-2026-91727Google Chrome: Use of Incorrectly-Resolved Name or Reference
- CVE-2026-91735Google Chrome: Incorrect Authorization
- CVE-2026-91728Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-91715Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-91731Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-91741Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-91709Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-91711Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-91721Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page
- CVE-2026-91749Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page
- CVE-2026-91724Google Chrome: Use After Free
- CVE-2026-91734Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program
- CVE-2026-91736Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-91710Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page
- CVE-2026-91718Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page
- CVE-2026-91716Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page
- CVE-2026-91729Google Chrome: Use After Free
- CVE-2026-91737Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-91745Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
- CVE-2026-91722Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page
- CVE-2026-91714Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page
- CVE-2026-91725Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page
- CVE-2026-91739Google Chrome: Missing Authorization
- CVE-2026-91713Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page
- CVE-2026-91730Google Chrome: Incomplete Cleanup
- CVE-2026-91746Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page
- CVE-2026-91740Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page
- CVE-2026-91708Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page
- CVE-2026-91717Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app
- CVE-2026-91733Google Chrome: Improper Check for Unusual or Exceptional Conditions
- CVE-2026-91747Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page
- CVE-2026-91720Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page
- CVE-2026-91744Google Chrome: Time-of-check Time-of-use (TOCTOU) Race Condition
Source and provenance
Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 26 Sept 2026, 16:54 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗