Google released Chrome 147.0.7727.101/.102 for desktop and 147.0.7727.101 for Android to fix a broad set of browser vulnerabilities, with the desktop advisory covering 31 security issues and multiple Critical and High severity bugs. The patched set includes remote code execution and memory-corruption flaws such as CVE-2026-6299 in Prerender, CVE-2026-6297 in Proxy, CVE-2026-6300 in Blink CSS, CVE-2026-6307 and CVE-2026-6363 in V8, CVE-2026-6361 in PDFium, and several use-after-free bugs in Video, Forms, FileSystem, Cast, Permissions, and XR components. Google said Android inherits the same security fixes as the corresponding desktop release unless otherwise noted, and affected versions span Chrome builds prior to 147.0.7727.101 on Linux and Android and prior to 147.0.7727.101/.102 on Windows and macOS.
Several of the flaws could be used in exploit chains to cross Chrome security boundaries, including sandbox escape paths in GPU, Viz, Dawn WebGPU, Accessibility, Graphite, and Proxy components through CVE-2026-6314, CVE-2026-6309, CVE-2026-6310, CVE-2026-6311, CVE-2026-6304, and CVE-2026-6297. Public technical details for many Chromium issues remain restricted while patches propagate, and no confirmed in-the-wild exploitation was cited for these specific April fixes, though multiple reports note Chrome’s recent zero-day activity and the likelihood of rapid weaponization of memory-safety bugs. The Canadian Centre for Cyber Security urged organizations to review Google’s advisory and apply updates promptly, while downstream Chromium-based browsers may remain exposed until they ship their own patched releases.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-15, the Canadian Centre for Cyber Security published advisory AV26-358 about Google's Chrome desktop security update. The notice identified affected versions prior to 147.0.7727.101/102 on Windows and Mac and prior to 147.0.7727.101 on Linux, and urged users and administrators to apply updates.
On 2026-04-15, Google released Chrome 147.0.7727.101/.102 for desktop platforms and 147.0.7727.101 for Android. The updates addressed a broad set of vulnerabilities, with multiple references stating the stable-channel release included 31 security fixes affecting components such as Proxy, Prerender, Video, FileSystem, Forms, Cast, Permissions, Viz, Dawn/WebGPU, GPU, XR, PDFium, V8, and Accessibility.
On 2026-04-07, Anders Hartvoll Ruud authored commit c34df82 to fix CVE-2026-6300 in Chrome's Blink CSS layout engine. The patch changed iteration logic, added validation helpers, and introduced a regression crashtest.
Google discovered and reported CVE-2026-6315 internally on 2026-04-03. The high-severity use-after-free in Chrome's Permissions component primarily affected Android exploitation scenarios.
CVE-2026-6360, a high-severity use-after-free in Chrome's FileSystem component, was reported by asjidkalam on 2026-03-31. Google later included the issue among 31 security fixes in its April 2026 stable update.
Google fixed CVE-2026-6299 in commit 8c1ead5a699f53f1915f3187d2bcfac725c46815, authored by Hiroki Nakagawa on 2026-03-30. The bug was a critical use-after-free in Chrome's Prerender feature that could allow remote code execution via crafted HTML.
CVE-2026-6307, a V8 Turbofan type confusion vulnerability, was reported by Project WhatForLunch on 2026-03-29. Google later shipped fixes for the issue in the April 15, 2026 Chrome 147 security release.
Google's later April 2026 patch cycle included CVE-2026-6302, a high-severity use-after-free in Chrome's Video component. The vulnerability was explicitly described as having been reported by researcher Syn4pse on 2026-03-24.
On 2025-09-23, Google announced Chrome 140.0.7339.207/.208 for Windows and Mac and 140.0.7339.207 for Linux. The release patched three High-severity V8 issues: CVE-2025-10890, CVE-2025-10891, and CVE-2025-10892.
On 2025-09-17, Google released Chrome 140.0.7339.185/.186 for Windows and Mac and 140.0.7339.185 for Linux. The update fixed four High-severity vulnerabilities in V8, Dawn, WebRTC, and ANGLE, and Google said an exploit existed in the wild for CVE-2025-10585.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
22 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcechromereleases.googleblog.com
Open sourcezeropath.com
Open sourcechromereleases.googleblog.com
Open sourcechromereleases.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.