BlackTreeCVE IntelligenceOfficial source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com
Chrome Releases: Stable Channel Update for Desktop
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-7979Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page
- CVE-2026-7910Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page
- CVE-2026-7902Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-7915Insufficient data validation in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page
- CVE-2026-7959Google Chrome — Protection Mechanism Failure
- CVE-2026-7916Google Chrome — Improper Input Validation
- CVE-2026-7946Google Chrome — Protection Mechanism Failure
- CVE-2026-7932Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictions via a crafted HTML page
- CVE-2026-7989Google Chrome — Improper Input Validation
- CVE-2026-8018Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic
- CVE-2026-7981Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file
- CVE-2026-7978Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic
- CVE-2026-7990Google Chrome — Improper Input Validation
- CVE-2026-7994Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file
- CVE-2026-7997Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file
- CVE-2026-8001Google Chrome — Use After Free
- CVE-2026-8007Google Chrome — Improper Input Validation
- CVE-2026-7923Google Chrome — Out-of-bounds Write
- CVE-2026-7922Use after free in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-7920Google Chrome — Use After Free
- CVE-2026-7919Google Chrome — Use After Free
- CVE-2026-7918Google Chrome — Use After Free
- CVE-2026-7917Google Chrome — Use After Free
- CVE-2026-7914Google Chrome — Access of Resource Using Incompatible Type ('Type Confusion')
- CVE-2026-7913Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file
- CVE-2026-7911Google Chrome — Use After Free
- CVE-2026-7908Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
- CVE-2026-7905Google Chrome — Improper Input Validation
- CVE-2026-7903Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-7900Google Chrome — Heap-based Buffer Overflow
- CVE-2026-7907Use after free in DOM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-7906Use after free in SVG in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-7921Use after free in Passwords in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page
- CVE-2026-7897Google Chrome — Use After Free
- CVE-2026-7896Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
- CVE-2026-7929Google Chrome — Use After Free
- CVE-2026-7928Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-7927Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-7925Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file
- CVE-2026-7926Use after free in PresentationAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-7938Use after free in CSS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-7940Google Chrome — Use After Free
- CVE-2026-7948Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file
- CVE-2026-7951Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
- CVE-2026-7956Google Chrome — Use After Free
- CVE-2026-7957Google Chrome — Out-of-bounds Write
- CVE-2026-7963Google Chrome — Protection Mechanism Failure
- CVE-2026-7967Google Chrome — Improper Input Validation
- CVE-2026-7970Google Chrome — Use After Free
- CVE-2026-7973Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
Source and provenance
Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗