Google has released Chrome 148 to the stable channel for Windows, macOS, Linux, and Android, patching 127 security vulnerabilities in one of the browser’s largest security update batches. The release fixes three Critical flaws: CVE-2026-7896, an integer overflow in Blink that could lead to heap corruption via a crafted HTML page, plus CVE-2026-7897 and CVE-2026-7898, two use-after-free bugs affecting Mobile and Chromoting. Google said no active exploitation had been reported at release, but urged users to update to 148.0.7778.96/97 immediately; Canada’s cyber agency also advised administrators to apply the update for affected desktop versions prior to those builds.
The advisory also covers more than two dozen high-severity issues across major Chromium components including V8, ANGLE, WebRTC, GPU, Skia, UI, DevTools, Printing, Audio, ChromeDriver, and AdFilter, many involving memory-safety errors such as use-after-free, type confusion, out-of-bounds access, and insufficient validation of untrusted input. Public CVE records tied to the release include CVE-2026-7987, CVE-2026-7988, CVE-2026-7991, CVE-2026-7992, CVE-2026-7995, CVE-2026-8000, CVE-2026-8001, CVE-2026-8002, CVE-2026-8016, and CVE-2026-8018, several of which could enable code execution inside Chrome’s sandbox or, in some cases, potential sandbox escape. Google credited internal testing tools such as fuzzers and sanitizers along with external researchers, paid at least $138,000 in bug bounties, and withheld details for some issues until most users receive fixes; because the bugs affect Chromium, downstream browsers and enterprise Chromium deployments may also need corresponding updates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Reporting on the rollout emphasized that Chrome 148 was one of the browser's largest recent security releases, with 127 fixes spanning Critical, High, Medium, and Low severity issues. Google said no active exploitation had been reported at release time and urged immediate updating across Windows, macOS, Linux, and Chromium-based environments.
Multiple CVE records tied to the Chrome 148 release were analyzed or updated with descriptions, affected platforms, CWE classifications, CVSS scores, and references to Google's advisory and Chromium issue tracker entries. These updates included flaws such as CVE-2026-7987, CVE-2026-7988, CVE-2026-7991, CVE-2026-7992, CVE-2026-7995, CVE-2026-8000, CVE-2026-8001, CVE-2026-8002, CVE-2026-8016, and CVE-2026-8018.
The Canadian Centre for Cyber Security published advisory AV26-426 warning that Chrome versions prior to 148.0.7778.96/97 were affected and urging users and administrators to apply Google's updates. The notice referenced Google's May 5 security advisory for Stable Channel Chrome for Desktop.
As part of the Chrome 148 release, Google said technical details for 21 vulnerabilities would remain restricted until a majority of users had updated. The release also credited external researchers and noted bug bounty payouts tied to the disclosed flaws.
Google published the Chrome 148 stable channel update for desktop, releasing version 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and Mac. The advisory disclosed 127 security fixes, including three critical vulnerabilities affecting Blink, Mobile, and Chromoting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethecyberthrone.in
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcechromereleases.googleblog.com
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.