BlackTreeCVE IntelligenceOfficial source evidencechromereleases.googleblog.comVersioned article
Official source article · chromereleases.googleblog.com
Chrome Releases: Stable Channel Update for Desktop
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherchromereleases.googleblog.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-87491Google Chromium V8 Out of Bounds Write Vulnerability
- CVE-2026-87544Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page
- CVE-2026-87647Google Chrome: Use of Uninitialized Resource
- CVE-2026-87576Google Chrome: Use of Uninitialized Resource
- CVE-2026-87525Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program
- CVE-2026-87555Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page
- CVE-2026-87564Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page
- CVE-2026-87586Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page
- CVE-2026-87592Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page
- CVE-2026-87596Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page
- CVE-2026-87435Google Chrome: Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2026-87657Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page
- CVE-2026-87608Google Chrome: Improper Certificate Validation
- CVE-2026-87551Google Chrome: Improper Certificate Validation
- CVE-2026-87571Google Chrome: Improper Certificate Validation
- CVE-2026-87575Google Chrome: Incorrect Authorization
- CVE-2026-87469Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic
- CVE-2026-87473Google Chrome: Incorrect Authorization
- CVE-2026-87546Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted file
- CVE-2026-87595Google Chrome: Server-Side Request Forgery (SSRF)
- CVE-2026-87627Google Chrome: Interpretation Conflict
- CVE-2026-87511Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension
- CVE-2026-87656Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page
- CVE-2026-87431Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension
- CVE-2026-87493Google Chrome: Missing Authorization
- CVE-2026-87468Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page
- CVE-2026-87584Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page
- CVE-2026-87591Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension
- CVE-2026-87610Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page
- CVE-2026-87626Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via crafted network traffic
- CVE-2026-87429Google Chrome: Missing Authorization
- CVE-2026-87561Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted Chrome extension
- CVE-2026-87519Google Chrome: Incorrect Authorization
- CVE-2026-87543Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page
- CVE-2026-87522Google Chrome: Missing Authorization
- CVE-2026-87645Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page
- CVE-2026-87471Google Chrome: Incorrect Authorization
- CVE-2026-87603Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page
- CVE-2026-87580Google Chrome: Incorrect Authorization
- CVE-2026-87475Google Chrome: Missing Authorization
- CVE-2026-87436Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension
- CVE-2026-87513Google Chrome: Missing Authorization
- CVE-2026-87560Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page
- CVE-2026-87534Google Chrome: Missing Authorization
- CVE-2026-87556Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page
- CVE-2026-87482Google Chrome: Cleartext Transmission of Sensitive Information
- CVE-2026-87590Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic
- CVE-2026-87464Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page
- CVE-2026-87649Google Chrome: User Interface (UI) Misrepresentation of Critical Information
- CVE-2026-87548Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page
Source and provenance
Original title: Chrome Releases: Stable Channel Update for Desktop. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗