← All stories
● Covered by 3 sources · 18 reportsMedium impact2 negative12 neutral

Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security

🔄 Updated 7d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Chrome 150 resolves 27 vulnerabilities, including 2 critical.
  • Critical flaws involve use-after-free in Ozone and Views.
  • Most vulnerabilities were discovered internally by Google.
  • Only 3 external reports received a total of $3,000 in rewards.
  • Since April, Google has fixed over 1,400 Chrome vulnerabilities.
  • Google released Chrome 151.
  • Chrome 151 resolves 15 vulnerabilities.
  • Chrome 151 critical flaws are buffer overflow bugs.
  • Chrome 152 patches over 300 vulnerabilities.
  • Chrome 152 includes 10 critical flaws.
  • Most Chrome 152 critical flaws are use-after-free issues.
  • Chrome 152 critical flaws are in Angle, Aura, Chromecast, Views, SafeBrowsing.
  • Chrome 152 includes 61 high severity flaws.
  • 299 of 327 weaknesses in Chrome 152 were discovered internally by Google.
  • Google used AI to discover vulnerabilities in Chrome 152.
  • Goodluck received $25,000 for CVE-2026-79282.
  • Google has patched over 2,000 Chrome vulnerabilities this year.
  • Google's advisory does not mention in-the-wild exploitation.
  • Chrome 152 update fixes 26 bugs.
  • Chrome 152 critical flaws are use-after-free in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352).
  • Chrome 152 update addresses 9 high-severity security defects.
  • Chrome 152 update includes 15 medium- and low-severity vulnerabilities.
  • Only 3 Chrome 152 flaws were reported by external researchers.
  • No bug bounty reward has been disclosed for Chrome 152 external reports.
  • Chrome 152 is rolling out as versions 152.0.7977.75/.76 for Windows and macOS.
  • Chrome 152 is rolling out as version 152.0.7977.75 for Linux.
  • Mozilla rolled out Firefox 155.
  • Firefox 155 patches 29 security defects.
  • Firefox 155 includes 13 high-severity use-after-free, sandbox escape, and memory corruption issues.
  • Firefox 155 flaws were addressed in GC, Navigation, Audio/Video, Security, WebGPU, Core & HTML, Grid components, and Firefox for Android.
  • Google released security updates for Chrome to fix 12 vulnerabilities.
  • CVE-2026-85046 is a type confusion bug in the V8 JavaScript engine.
  • CVE-2026-85046 is being actively exploited in the wild.
  • CVE-2026-85046 allows remote attackers to execute arbitrary code within the browser's sandbox.
  • CVE-2026-85046 has a CVSS score of 8.8.
  • Salvatore Gulizia discovered and reported CVE-2026-85046 on August 4, 2026.
  • Salvatore Gulizia received a $1,000 bug bounty for CVE-2026-85046.
  • CVE-2026-85046 is a V8 bug in compilers that leads to an array receiving the map PACKED_SMI_ELEMENTS.
  • CVE-2026-85046 is the sixth Chrome zero-day patched in 2026.
  • The other five zero-days are CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.
  • Chrome 152 update is version 152.0.7977.82/.83 for Windows and macOS.
  • Chrome 152 update is version 152.0.7977.82 for Linux.
  • Salvatore Gulizia is known online as "Serotav".
  • Google released an update to patch 230 security vulnerabilities.
  • CVE-2026-87491 is an actively exploited zero-day in the V8 JavaScript engine.
  • CVE-2026-87491 is an out-of-bounds bug in V8.
  • CVE-2026-87491 allowed remote code execution inside the sandbox via a crafted HTML page.
  • Jihyeon Jeong of Compsec Lab, Seoul National University, discovered CVE-2026-87491.
  • Jihyeon Jeong reported CVE-2026-87491 on August 6, 2026.
  • Jihyeon Jeong received a $2,500 bug bounty for CVE-2026-87491.
  • Google is aware an exploit for CVE-2026-87491 exists in the wild.
  • Google restricted access to bug details until most users are updated.
  • CVE-2026-87491 is the seventh Chrome zero-day patched in 2026.
  • Chrome 153 is rolling out as version 153.0.8010.36 for Windows and Linux.
  • Chrome 153 is rolling out as version 153.0.8010.37 for Mac.
  • CVE-2026-87491 is a medium-severity security defect.
  • Chrome 153 resolves 5 critical-severity vulnerabilities.
  • Chrome 153 critical flaws are use-after-free, out-of-bounds write, and buffer overflow in WebGL.
  • One Chrome 153 critical flaw is a use-after-free weakness in Cast.
  • Chrome 153 resolves 41 high-severity security defects.
  • Chrome 153 high-severity flaws include use-after-free, out-of-bounds read, incorrect/missing authorization, and race condition issues.
  • Chrome 153 resolves over 180 medium- and low-severity bugs.
  • Chrome 154 patches 108 vulnerabilities.
  • Chrome 154 includes 11 critical-severity bugs.
  • Chrome 154 critical flaws include buffer overflows in ANGLE and WebGL.
  • Chrome 154 critical flaws include out-of-bounds writes in GPU and WebGL.
  • Chrome 154 critical flaws include use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter.
  • Nine Chrome 154 critical issues were reported by external researchers.
  • 32 Chrome 154 flaws were reported externally.
  • Google paid $18,000 in bug bounty rewards for Chrome 154.
  • Chrome 154 includes 25 high-severity bugs.
  • Chrome 154 high-severity bugs include use-after-free, type confusion, uninitialized resource, and buffer overflow issues.
  • Chrome 154 high-severity bugs include missing authorization, UI misinterpretation, incorrect authorization, improper output encoding, race condition, and out-of-bounds write flaws.
  • Chrome 154.0.8037.92/.93 for Windows/macOS and 154.0.8037.92 for Linux were released.
  • Chrome 154 fixes 32 security defects.
  • Chrome 154 includes a critical buffer overflow in ANGLE (CVE-2026-102331).
  • CVE-2026-102331 was reported by an external researcher.
  • Chrome 154 addresses 25 high-severity security weaknesses.
  • Chrome 154 high-severity flaws include uninitialized resource and use-after-free vulnerabilities.
  • Chrome 154 fixes five high-severity type confusion flaws in V8 JavaScript and WebAssembly engine.
  • Chrome 154 fixes high-severity improper privilege management, UI misconfiguration, out-of-bounds read/write, XSS, and buffer overflow issues.
  • External researchers reported 15 Chrome 154 security holes.
  • Google paid $1,000 for a low-severity missing authorization bug in Payments.
  • Mozilla released Firefox 157.
  • Firefox 157 patches approximately 76 vulnerabilities.

Chrome 150 Update Enhances Security

Google has rolled out the latest version of its browser, Chrome 150, addressing 27 vulnerabilities to enhance user security. Among these, two critical flaws were resolved, specifically impacting the Ozone and Views components, both identified internally by Google. This update is crucial for maintaining browser integrity against potential cyber threats.

Addressing Critical Vulnerabilities

The two critical vulnerabilities concern use-after-free issues that can lead to browser instability and potential exploitation by attackers. Resolving such memory safety flaws is an ongoing priority for Google, as they are often targeted by sophisticated cyber threats.

Internal Discovery and Low Bug Bounty Rewards

Interestingly, the majority of the vulnerabilities were found by Google's internal team, reflecting a trend of reduced reliance on external discoveries. As a result, only three external findings from researchers were awarded bug bounties, totaling $3,000.

The report suggests that the use of AI might be enabling this internal trend, reducing the necessity for external contributions.

Significance of Regular Updates

Keeping Chrome updated is vital due to constant security threats capitalizing on memory safety flaws. Since April, over 1,400 vulnerabilities have been addressed in Chrome, emphasizing the importance of frequently checking for the latest browser updates to protect against exploitation.

Updates

🕒 2026-09-30 · new reporting from SecurityWeek
  • Chrome 154.0.8037.92/.93 for Windows/macOS and 154.0.8037.92 for Linux were released.
  • Chrome 154 fixes 32 security defects.
  • Chrome 154 includes a critical buffer overflow in ANGLE (CVE-2026-102331).
  • CVE-2026-102331 was reported by an external researcher.
  • Chrome 154 addresses 25 high-severity security weaknesses.
  • Chrome 154 high-severity flaws include uninitialized resource and use-after-free vulnerabilities.
  • Chrome 154 fixes five high-severity type confusion flaws in V8 JavaScript and WebAssembly engine.
  • Chrome 154 fixes high-severity improper privilege management, UI misconfiguration, out-of-bounds read/write, XSS, and buffer overflow issues.
  • External researchers reported 15 Chrome 154 security holes.
  • Google paid $1,000 for a low-severity missing authorization bug in Payments.
  • Mozilla released Firefox 157.
  • Firefox 157 patches approximately 76 vulnerabilities.
🕒 2026-09-23 · new reporting from SecurityWeek
  • Chrome 154 patches 108 vulnerabilities.
  • Chrome 154 includes 11 critical-severity bugs.
  • Chrome 154 critical flaws include buffer overflows in ANGLE and WebGL.
  • Chrome 154 critical flaws include out-of-bounds writes in GPU and WebGL.
  • Chrome 154 critical flaws include use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter.
  • Nine Chrome 154 critical issues were reported by external researchers.
  • 32 Chrome 154 flaws were reported externally.
  • Google paid $18,000 in bug bounty rewards for Chrome 154.
  • Chrome 154 includes 25 high-severity bugs.
  • Chrome 154 high-severity bugs include use-after-free, type confusion, uninitialized resource, and buffer overflow issues.
  • Chrome 154 high-severity bugs include missing authorization, UI misinterpretation, incorrect authorization, improper output encoding, race condition, and out-of-bounds write flaws.
🕒 2026-09-09 · new reporting from BleepingComputer, SecurityWeek
  • CVE-2026-87491 is the seventh Chrome zero-day patched in 2026.
  • Chrome 153 is rolling out as version 153.0.8010.36 for Windows and Linux.
  • Chrome 153 is rolling out as version 153.0.8010.37 for Mac.
  • CVE-2026-87491 is a medium-severity security defect.
  • Chrome 153 resolves 5 critical-severity vulnerabilities.
  • Chrome 153 critical flaws are use-after-free, out-of-bounds write, and buffer overflow in WebGL.
  • One Chrome 153 critical flaw is a use-after-free weakness in Cast.
  • Chrome 153 resolves 41 high-severity security defects.
  • Chrome 153 high-severity flaws include use-after-free, out-of-bounds read, incorrect/missing authorization, and race condition issues.
  • Chrome 153 resolves over 180 medium- and low-severity bugs.
🕒 2026-09-09 · new reporting from The Hacker News
  • Google released an update to patch 230 security vulnerabilities.
  • CVE-2026-87491 is an actively exploited zero-day in the V8 JavaScript engine.
  • CVE-2026-87491 is an out-of-bounds bug in V8.
  • CVE-2026-87491 allowed remote code execution inside the sandbox via a crafted HTML page.
  • Jihyeon Jeong of Compsec Lab, Seoul National University, discovered CVE-2026-87491.
  • Jihyeon Jeong reported CVE-2026-87491 on August 6, 2026.
  • Jihyeon Jeong received a $2,500 bug bounty for CVE-2026-87491.
  • Google is aware an exploit for CVE-2026-87491 exists in the wild.
  • Google restricted access to bug details until most users are updated.
🕒 2026-09-04 · new reporting from SecurityWeek, BleepingComputer
  • CVE-2026-85046 is the sixth Chrome zero-day patched in 2026.
  • The other five zero-days are CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.
  • Chrome 152 update is version 152.0.7977.82/.83 for Windows and macOS.
  • Chrome 152 update is version 152.0.7977.82 for Linux.
  • Salvatore Gulizia is known online as "Serotav".
🕒 2026-09-04 · new reporting from The Hacker News
  • Google released security updates for Chrome to fix 12 vulnerabilities.
  • CVE-2026-85046 is a type confusion bug in the V8 JavaScript engine.
  • CVE-2026-85046 is being actively exploited in the wild.
  • CVE-2026-85046 allows remote attackers to execute arbitrary code within the browser's sandbox.
  • CVE-2026-85046 has a CVSS score of 8.8.
  • Salvatore Gulizia discovered and reported CVE-2026-85046 on August 4, 2026.
  • Salvatore Gulizia received a $1,000 bug bounty for CVE-2026-85046.
  • CVE-2026-85046 is a V8 bug in compilers that leads to an array receiving the map PACKED_SMI_ELEMENTS.
🕒 2026-09-02 · new reporting from SecurityWeek
  • Chrome 152 update fixes 26 bugs.
  • Chrome 152 critical flaws are use-after-free in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352).
  • Chrome 152 update addresses 9 high-severity security defects.
  • Chrome 152 update includes 15 medium- and low-severity vulnerabilities.
  • Only 3 Chrome 152 flaws were reported by external researchers.
  • No bug bounty reward has been disclosed for Chrome 152 external reports.
  • Chrome 152 is rolling out as versions 152.0.7977.75/.76 for Windows and macOS.
  • Chrome 152 is rolling out as version 152.0.7977.75 for Linux.
  • Mozilla rolled out Firefox 155.
  • Firefox 155 patches 29 security defects.
  • Firefox 155 includes 13 high-severity use-after-free, sandbox escape, and memory corruption issues.
  • Firefox 155 flaws were addressed in GC, Navigation, Audio/Video, Security, WebGPU, Core & HTML, Grid components, and Firefox for Android.
🕒 2026-08-26 · new reporting from SecurityWeek
  • Chrome 152 patches over 300 vulnerabilities.
  • Chrome 152 includes 10 critical flaws.
  • Most Chrome 152 critical flaws are use-after-free issues.
  • Chrome 152 critical flaws are in Angle, Aura, Chromecast, Views, SafeBrowsing.
  • Chrome 152 includes 61 high severity flaws.
  • 299 of 327 weaknesses in Chrome 152 were discovered internally by Google.
  • Google used AI to discover vulnerabilities in Chrome 152.
  • Goodluck received $25,000 for CVE-2026-79282.
  • Google has patched over 2,000 Chrome vulnerabilities this year.
  • Google's advisory does not mention in-the-wild exploitation.
🕒 2026-08-19 · new reporting from SecurityWeek
  • Google released Chrome 151.
  • Chrome 151 resolves 15 vulnerabilities.
  • Chrome 151 critical flaws are buffer overflow bugs.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~5 min · 3 stories · Oct 07

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Google released Chrome versions 154.0.8037.92/.93 for Windows/macOS and 154.0.8037.92 for Linux, fixing 32 security defects including a critical buffer overflow. Mozilla released Firefox 157 and Firefox ESR updates, addressing approximately 76 vulnerabilities, many of which are high-severity use-after-free and sandbox escape bugs. These updates are critical for user security as they resolve numerous potential exploits, though none are reported as actively exploited.

Google released Chrome 154, addressing 108 vulnerabilities, with 11 critical-severity bugs. Users should update their browsers to mitigate potential security risks from these flaws.

Google released Chrome 153, addressing 230 vulnerabilities, including an actively exploited zero-day (CVE-2026-87491) in the V8 JavaScript engine. This marks the seventh zero-day patched in Chrome this year, highlighting ongoing efforts to secure the browser against known exploits.

Google released an update for Chrome to patch 230 security vulnerabilities, including CVE-2026-87491, an actively exploited zero-day in the V8 JavaScript engine. This vulnerability allowed remote code execution inside the sandbox via a crafted HTML page, making the update critical for user security.

Google released an emergency update for Chrome to patch a new zero-day vulnerability, CVE-2026-87491, which is actively being exploited. This marks the seventh such vulnerability addressed by Google since the beginning of the year, indicating ongoing threats to browser security.

Google released an urgent update for the Chrome browser to fix a high-severity zero-day vulnerability (CVE-2026-85046) in its V8 JavaScript engine, which is actively being exploited. This flaw, a type confusion issue, could allow remote code execution through malicious web pages, making immediate updates critical for user security.

Google released Chrome 152 security updates addressing 12 vulnerabilities, including an actively exploited zero-day, CVE-2026-85046. This type confusion flaw in Chrome's V8 JavaScript engine could lead to remote code execution and is the sixth Chrome zero-day patched in 2026, indicating ongoing threats to browser security.

Google released security updates for Chrome to fix 12 vulnerabilities, including CVE-2026-85046, a type confusion bug in the V8 JavaScript engine that is being actively exploited. This patch is critical as the vulnerability allows remote attackers to execute arbitrary code within the browser's sandbox, impacting user security.

Google and Mozilla have released updates for Chrome and Firefox, addressing numerous critical and high-severity security flaws. These patches are important for user security, as they fix vulnerabilities that could potentially be exploited.

Google released Chrome 152, addressing over 300 vulnerabilities, including 10 critical flaws. The majority of these vulnerabilities were discovered internally by Google using AI, indicating an increased rate of internal security findings.

Google and Mozilla have released security updates for Chrome and Firefox, addressing multiple critical and high-severity vulnerabilities. These updates are important for user security as they fix flaws that could lead to code execution, privilege escalation, and information disclosure.

Google released Chrome 151, addressing 41 critical and high-severity vulnerabilities, including six critical flaws and 35 high-severity issues. This update is important for user security as it resolves memory safety bugs and other vulnerabilities that could lead to data corruption or arbitrary code execution.

Google recently fixed 1,442 security flaws across Chrome versions 149, 150, and 151, a number exceeding the total fixes from the prior 23 updates. This surge in vulnerability discovery is attributed to large language models accelerating bug reporting, prompting Google to increase its security release cadence and explore automated patching methods.

Google released Chrome 151, addressing 370 vulnerabilities, including seven critical-severity bugs and numerous high-severity issues. This update is significant for maintaining browser security and protecting users from potential exploits.

Google has released Chrome 150, patching seven memory safety bugs, including critical use-after-free vulnerabilities. This update is crucial as memory safety issues have been targeted by cyber threats, and over 1,400 Chrome vulnerabilities have been addressed since April.

Mozilla, Google, and Adobe released updates fixing multiple critical security vulnerabilities across their platforms. These updates address flaws that could lead to arbitrary code execution, privilege escalation, and heap corruption, thus mitigating significant risks for users across different services.

Google and Mozilla have released updates for Chrome 150 and Firefox 152, addressing critical vulnerabilities. Firefox fixes two critical bugs with public exploit code, while Chrome addresses 15 vulnerabilities including two critical security issues related to memory handling.

Google released Chrome 150, addressing 27 vulnerabilities, notably two critical flaws in Ozone and Views. This update highlights an ongoing trend of Google discovering most flaws internally, with rewards for external submissions decreasing as a result.