Google released a Chrome Stable security update for desktop that fixes two high-severity vulnerabilities that could enable arbitrary code execution or denial-of-service conditions. The update advances Chrome to 144.0.7559.132/.133 on Windows and macOS and 144.0.7559.132 on Linux, with a staged rollout over days to weeks; exploitation is described as typically requiring a victim to visit a specially crafted website that triggers the bug in the renderer context.
The patched issues are CVE-2026-1862, a type confusion flaw in the V8 JavaScript/WebAssembly engine (reported by researcher Chaoyuan Peng / @ret2happy) that can enable out-of-bounds memory access and potentially code execution, and CVE-2026-1861, a heap buffer overflow in the libvpx VP8/VP9 video codec library that could be triggered by crafted media content to crash the browser/system or potentially hijack control flow. Google is restricting detailed bug information and links until most users have applied the fix to reduce the risk of rapid exploit development via patch diffing.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Google identified CVE-2026-1862 as a type confusion flaw in the V8 JavaScript engine and CVE-2026-1861 as a heap buffer overflow in libvpx, both of which could lead to crashes and potentially code execution. The company said detailed technical information would be temporarily restricted until most users had updated and did not report active exploitation in the wild.
Google released a Chrome Stable channel desktop update to patch two high-severity memory-corruption vulnerabilities, CVE-2026-1861 and CVE-2026-1862. The rollout updated Chrome to 144.0.7559.132/.133 on Windows and macOS and 144.0.7559.132 on Linux.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.