Google released a Stable Channel security update for Chrome Desktop, fixing a broad set of vulnerabilities in versions prior to 149.0.7827.53/54 on Windows and Mac and 149.0.7827.53 on Linux, while related records also show Chrome on Android was affected before 149.0.7827.53. The Canadian Centre for Cyber Security urged users and administrators to apply the update, and public CVE entries tie the release to numerous flaws across V8, Blink, WebRTC, Compositing, Dawn, DevTools, GPU, PDFium, Extensions, Media, TabStrip, Cast, LiveCaption, Google Lens, CSS, and USB. Many of the issues are memory-safety bugs such as use-after-free, out-of-bounds write/read, integer overflow, and type confusion, with several carrying CVSS vectors indicating high impact to confidentiality, integrity, and availability.
The patched vulnerabilities include remote code execution inside Chrome’s sandbox through crafted HTML pages or malicious PDF files, information disclosure from process memory, UI spoofing, navigation restriction bypass, privilege escalation on adjacent networks, and multiple paths that could aid sandbox escape after renderer compromise. Notable examples include CVE-2026-11188 in Android USB that could potentially enable sandbox escape, CVE-2026-11256 in the GPU component, CVE-2026-11173 in V8, CVE-2026-11118 and CVE-2026-11074 in WebRTC, and several PDFium bugs including CVE-2026-11303, CVE-2026-11305, and CVE-2026-11307. Visible metadata from one additional report also points to CVE-2026-10881, linked to Chrome 149, the ANGLE layer, and memory corruption involving GPU buffer overflow and use-after-free.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
26 events from the most recent confirmed update back to the earliest known activity.
On June 12, 2026, CVE-2026-12028 was documented as a high-severity use-after-free flaw in Chrome's GPU component on Android affecting versions prior to 149.0.7827.115. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record was updated with CWE-416 and CVSS v3.1 details.
On June 12, 2026, CVE-2026-12022 was documented as a high-severity race condition in Chrome's Safe Browsing component on Mac affecting versions prior to 149.0.7827.115. The flaw could allow a remote attacker, after compromising the renderer process, to potentially escape Chrome's sandbox via a malicious file; the record includes CWE-362 and CVSS v3.1 details.
Google shipped a new Stable Channel desktop update for Chrome 149, releasing version 149.0.7827.114/.115 for Windows and Mac and 149.0.7827.114 for Linux. The update fixes 28 security flaws, including five critical vulnerabilities affecting Core, DigitalCredentials, WebMIDI, Accessibility, and GPU components.
On June 11, 2026, CVE-2026-12023 was recorded as a high-severity use-after-free flaw in Chrome's GPU component on Mac affecting versions prior to 149.0.7827.115. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record was later updated with CWE-416 and CVSS v3.1 details.
On June 11, 2026, CVE-2026-12030 was documented as a high-severity out-of-bounds write flaw in Chrome's GPU component on Android affecting versions prior to 149.0.7827.115. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record was later updated with CWE-122 and CVSS v3.1 details.
On June 11, 2026, CVE-2026-12019 was documented as a high-severity heap buffer overflow in Chrome's Codecs component affecting Linux and ChromeOS versions prior to 149.0.7827.115. The flaw could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record was later updated with CWE-787 and CVSS v3.1 details.
On June 9, 2026, references and metadata were added for CVE-2026-11700, a high-severity use-after-free flaw in Chrome's Tracing component affecting versions prior to 149.0.7827.103. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape the sandbox; the record includes CWE-416 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11663, a high-severity use-after-free flaw in Chrome's Skia component affecting versions prior to 149.0.7827.103. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record includes CWE-416 and CVSS v3.1 details.
On June 9, 2026, references and metadata were added for CVE-2026-11652, a high-severity use-after-free flaw in Chrome's Extensions component affecting versions prior to 149.0.7827.103. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape the sandbox; the record includes CWE-416 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11662, a high-severity type confusion flaw in Chrome's Bindings component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside the browser sandbox; the record was later updated with CWE-843 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11687, a high-severity use-after-free flaw in Chrome's Dawn component on Mac affecting versions prior to 149.0.7827.103. The issue could allow a remote attacker to trigger heap corruption via a crafted HTML page, and the record includes CWE-416 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11698, a high-severity use-after-free flaw in Chrome's Bluetooth component on Mac affecting versions prior to 149.0.7827.103. The issue could allow a remote attacker to trigger heap corruption via a crafted HTML page, and the record includes CWE-416 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11651, a high-severity use-after-free flaw in Chrome's Network component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside Chrome's sandbox; the record includes CWE-416 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11647, a high-severity use-after-free flaw in Chrome's Printing component on Android affecting versions prior to 149.0.7827.103. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape the sandbox; the record includes CWE-416 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11674, a high-severity use-after-free flaw in Chrome's Guest View component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside Chrome's sandbox; the record includes CWE-416 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11680, a high-severity use-after-free flaw in Chrome's Media component on Windows affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside Chrome's sandbox; the record was updated with CWE-416 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11657, a high-severity use-after-free flaw in Chrome's Payments component on Mac affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside Chrome's sandbox.
On June 9, 2026, references were added for CVE-2026-11673, a high-severity use-after-free flaw in Chrome's InterestGroups component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside the browser sandbox.
On June 9, 2026, references were added for CVE-2026-11643, a use-after-free flaw in Chrome's Proxy component affecting versions prior to 149.0.7827.103. The issue could allow remote attackers to execute arbitrary code via malicious network traffic, and the record was later enriched with CWE-416 and CVSS v3.1 details.
On June 9, 2026, references were added for CVE-2026-11688, a high-severity inappropriate implementation flaw in Chrome's SVG component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow arbitrary code execution inside Chrome's sandbox.
On June 9, 2026, references were added for CVE-2026-11683, a high-severity use-after-free flaw in Chrome WebCodecs affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote code execution inside Chrome's sandbox.
On June 5, 2026, many of the Chrome CVE entries were updated with CVSS v3.1 vectors, CWE mappings, descriptions, and references to the Chrome Releases blog and Chromium issue tracker. This added technical detail for both the June 4 and June 5 vulnerability records.
On June 5, 2026, Google received additional CVE records for Chrome vulnerabilities affecting DevTools, GPU, PDFium, TabStrip, LiveCaption, Cast, and other components. These newly received entries expanded the set of flaws associated with the Chrome 149.0.7827.53 update cycle.
On June 4, 2026, Google received and recorded an initial batch of Chrome vulnerability entries affecting components including Dawn, V8, Blink, WebRTC, Media, CSS, Extensions, Compositing, and Android USB. These records covered flaws fixed in versions prior to Chrome 149.0.7827.53.
On June 3, 2026, the Canadian Centre for Cyber Security published advisory AV26-544, urging users and administrators to review Google's Chrome advisory and apply updates when available. The notice highlighted affected desktop versions on Windows, Mac, and Linux.
Google published a security advisory on June 2, 2026 for Stable Channel Chrome for Desktop, fixing vulnerabilities in versions prior to 149.0.7827.53/54 on Windows and Mac and prior to 149.0.7827.53 on Linux. The advisory is referenced across multiple CVE records tied to this stable channel update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
49 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.