Google released a Chrome Stable desktop update to version 149.0.7827.200/201 for Windows and Mac and 149.0.7827.200 for Linux, patching three high-severity vulnerabilities: CVE-2026-13281, an integer overflow in Mojo; CVE-2026-13282, a use-after-free in Payments; and CVE-2026-13283, a use-after-free in AdFilter. Google said technical details and exploit information may remain restricted until most users have updated or any affected third-party dependencies are also patched.
Advisories said the flaws could allow attackers to cause denial of service, bypass security restrictions, or potentially achieve arbitrary code execution via a crafted HTML page. Sector guidance urged organizations to validate and deploy the update quickly, while Google noted that many Chrome security issues are identified with internal and open-source testing tools including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
EG-FinCIRT published a notice about the Chrome update, identifying version 149.0.7827.200/201 for Windows and Mac and 149.0.7827.200 for Linux. The advisory highlighted that the patched flaws could enable denial of service, security restriction bypass, or arbitrary code execution via a crafted HTML page, and urged organizations to deploy the patch after testing.
Google announced a Chrome Stable channel update for Windows, Mac, and Linux that patched three high-severity vulnerabilities: CVE-2026-13281 in Mojo, CVE-2026-13282 in Payments, and CVE-2026-13283 in AdFilter. Google said technical details may remain restricted until most users receive the fix or affected third-party dependencies are patched.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
egfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourcechromereleases.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.